ovb.at

.at crawl

First seen 2026-05-31 · Last seen 2026-06-01 · ok HTTP/1.1 200 1538 ms crawled 2026-06-01

DE · 192.109.14.226 · AS24861 SITS Deutschland GmbH

Reputation 100/100

Classifying

HTML metadata

Title
OVB Allfinanzvermittlungs GmbH
Description
Ob Vorsorge, Absicherung oder Vermögensstrategie – bei Finanzfragen stehen wir Ihnen persönlich zur Seite. Jetzt informieren!
Language
de-AT
Generator
TYPO3 CMS
Canonical
https://www.ovb.at/

Technology

Server
Apache
jQuery
1.10.2 known XSS (<3.5)

Social

Contact

Phone
Address
Sirona Straße 4/1/C, A-5071, Wals b. Salzburg, Salzburg, AT

DNS records live

NS
  • ns-1327.awsdns-37.org
  • ns-1682.awsdns-18.co.uk
  • ns-310.awsdns-38.com
  • ns-600.awsdns-11.net
MX
  • 10 ovb-at.onice.io
TXT
Show 4 TXT records
  • offensity-domain-verification=101b3c9103f0224856b828f5b7d628a17b6fe4ba2b619420e2d21686be62dd9e
  • pqs9zz7t135yn1hdk4fllpwnz9s8ffkj
  • pxh4xkjyd198vcl3bbr6w695zvjhd0cn
  • tpgl76fd2jsmm10k3rrhd3yv6pgsn72k
Verified for
  • Adobe
  • Google
  • Zoom

Email authentication strong

SPF
v=spf1 mx include:icw.ovb.email include:news.ovb.email include:spf.flowmailer.net include:bizmail.at include:_spf.a-fk.de include:csa.wwwserver.net -all
strict (-all)
DMARC
v=DMARC1; p=reject; pct=100; rua=mailto:dmarc@ovb-mail.eu; fo=1
policy: reject (enforced)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxGfEhuZfAI/WNXvvYbxhRyjB9MkejkQHbEsmPA379F1KfsyX4GzqhI9gR2F+edYXzhaowi1kCvRxRsiYP+…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDL3DWELPtnBH027sJHNJlwHmy9o/EImPBVxf/5KdAy2osKRA3QQ1pFkKszfksQU363dmM2jwXH0Pq9WmAqTVoZOl…
selectors probed

Certificate (current)

R13
from 2026-05-24 to 2026-08-22
Expires in 79 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.ovb.at/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
sameorigin
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'nonce-tbUlVeDLwIBitpEkb3V-GoYKqW2gBCWjCIhC_1zo9qIcySEJJgLwMQ' https://*.googleapis.com https://jawj.github.io https://cdn.jsdelivr.net 'sha256-3bzWVxQE32IZQKH9eh8KzyHuhXOlMrboDVVBRd0fWTU=' 'wasm-unsafe-eval' 'sha256-Uj/v88tG3kktFGTzlVxe8oOKd3rg17YwEeVwFtPNtvE=' 'sha256-zu3ANnsVKRPwuUxCsY2aAByDeSVTg3KB3pcmSsb67AI=' 'sha256-JXt6b93gjalKfwMIZlg5nLEkgmYKj22qSb05RknjlZI=' 'sha256-uN+YOHjdUovcjm9nwBAXDI94BQ2i+nFL2YjVmn2UPdc=' 'sha256-V3P2jXDGQY0t+Q+2Y4DVjzC2b8+cV5FGx/+w5KNd9SE=' https://www.ovb.at 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com https://www.facebook.com https://*.linkedin.com https://*.google.de https://*.google-analytics.com https://*.googletagmanager.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.frcapi.com https://*.immo-export.at ht
strict-transport-security
max-age=31536000; includeSubDomains

Links to (7)

Linked from (1)