styria-wohnbau.at
HTML metadata
Technology
- Server
- nginx
Contact
- Phone
DNS records live
- NS
-
- ns1.kt-net.at
- ns2.kt-net.at
- MX
-
- 10 styria.in.tmes.trendmicro.eu
- TXT
-
tmes=bd2b48b6e67b62659b6f6e0d932cf9ef
Email authentication weak
- SPF
-
v=spf1 include:_spf.kt-net.at include:spf.tmes.trendmicro.com mx a ip4:85.31.9.48/28 ip4:85.233.104.158 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' data: *.google-analytics.com *.gstatic.com *.googleapis.com *.ggpht.com; script-src 'self' blob: 'unsafe-eval' 'unsafe-inline' *.google-analytics.com *.gstatic.com *.googleapis.com *.jquery.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.gstatic.com *.googleapis.com *.ggpht.com; base-uri 'self'; frame-src 'self' *.vimeo.com *.youtube-nocookie.com *.google.com *.ggpht.com *.googlevideo.com; frame-ancestors 'self'; style-src 'self' 'unsafe-inline' 'report-sample'; report-uri https://www.styria-wohnbau.at/@http-reporting?csp=report&requestTime=1780223134551934&requestHash=8a5e37ffa00b85b1d709910541fed5eba5cd66bd- strict-transport-security
max-age=864000
Links to (4)
- siwa.at×1
- sgs.com×1
- ooe-gbv.at×1
- google.com×1