linztermine.at
HTML metadata
Technology
- Server
- Apache
- Stack
- Java
Social
Contact
DNS records live
- NS
-
- dns1.linz.at
- dns2.linz.at
- MX
-
- 10 mail.ugl.linz.at
- TXT
-
have-i-been-pwned-verification=05e0390efce27be52ff9c6363435453a
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 redirect=_spf.ugl.linz.atmissing all - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
frame-ancestors 'self'; block-all-mixed-content; default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' https://m.youtube.com https://otc.tourdata.at https://stats.linz.at https://www.youtube.com https://www.gstatic.com https://www.google.com https://cdnjs.cloudflare.com; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; frame-src 'self' *.youtube.com www.youtube-nocookie.com www.google.com; child-src 'self' www.youtube.com; img-src 'self' data: blob: *.ytimg.com *.youtube.com mapsneu.wien.gv.at *.linz.at https://ot.tourdata.at; font-src 'self' data:; connect-src 'self' mapsneu.wien.gv.at ot.tourdata.at stats.linz.at www.google.com; manifest-src 'self'; base-uri 'self'; form-action 'self'; media-src 'self'; prefetch-src 'self'; worker-src 'self'; report-uri https://csp-report.linz.at- strict-transport-security
max-age=15552000
Links to (3)
- facebook.com×1
- instagram.com×1
- linz.at×1
Linked from (2)
- moescape.com×1
- linz.at×1