projektkraft.at

.at crawl

First seen 2026-05-28 · Last seen 2026-05-31 · ok HTTP/1.1 200 505 ms crawled 2026-05-31

DE · 195.201.242.139 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Generalunternehmer für Ladenbau & Innenausbau
Description
B2B-Generalunternehmer für Ladenbau und Innenausbau: Gesamtumsetzung, Rollout-Kompetenz und verlässliche Projektabwicklung für Filialisten und Marken.
Language
de-DE
Generator
WPML ver:4.9.2.1 stt:1,4,3,27;
Canonical
https://www.projektkraft.at/
Translations
  • de
  • en
  • fr

Open Graph

url
https://www.projektkraft.at/
title
Generalunternehmer für Ladenbau & Innenausbau
locale
de_DE
site name
Projekt Kraft
description
B2B-Generalunternehmer für Ladenbau und Innenausbau: Gesamtumsetzung, Rollout-Kompetenz und verlässliche Projektabwicklung für Filialisten und Marken.

Technology

Server
nginx
CMS
WordPress
jQuery
3.7.1

Third-party hosts loaded (1)

  • secure.gravatar.com×3

Social

Contact

Email
Phone

DNS records live

NS
  • dns1.a1.net
  • dns2.a1.net
  • dns3.a1.net
MX
  • 10 projektkraft-at.mail.protection.outlook.com
TXT
  • ppe-d6e03544fe3796999320f3c4dc96e8c73f6bb19d
  • jtn5nilv01aagk931a8m7t2lpg
  • knowbe4-site-verification=da4d9ad28ef06508afe0ce8caf4a13d6
Verified for
  • Microsoft 365

Email authentication weak

SPF
v=spf1 mx a ip4:91.114.7.120 ip4:82.218.177.179 ip4:91.114.7.121 include:_spf-eu.ppe-hosted.com include:spf.protection.outlook.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R12
from 2026-05-17 to 2026-08-15
Expires in 75 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.projektkraft.at/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; connect-src *; frame-ancestors 'self' *
strict-transport-security
max-age=63072000; includeSubDomains; preload

Links to (8)

Linked from (3)