vav.at
HTML metadata
Technology
- Server
- nginx
- jQuery
- 1.11 known XSS (<3.5)
Third-party hosts loaded (3)
- download.digiaccess.org×1
- siegel.ausgezeichnet.org×1
- www.vavpro.at×1
Social
DNS records live
- NS
-
- ns-1359.awsdns-41.org
- ns-1709.awsdns-21.co.uk
- ns-385.awsdns-48.com
- ns-520.awsdns-01.net
- MX
-
- 10 mail.vav.at
- TXT
-
QuoVadis=700cf104-fcba-454e-b645-bd97dec23b4bQuoVadis=f897e8f3-6ed5-42b7-b272-7082e341a50d
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 redirect=23v7t4dy._spf._d.mim.ecmissing all - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:718d4c8d4413921@rep.dmarcanalyzer.com; ruf=mailto:718d4c8d4413921@for.dmarcanalyzer.com; fo=1;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 150 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- weak frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, ALLOW-FROM https://beta.vav.at, ALLOW-FROM https://beta-mein.vav.at, ALLOW-FROM https://beta.vavpro.at, ALLOW-FROM https://secure.vav.at, ALLOW-FROM https://abnahme.aforms2web.com, ALLOW-FROM https://www.vav.at, ALLOW-FROM https://www.vavpro.at, ALLOW-FROM https://mein.vav.at, ALLOW-FROM https://vav-abnahme.aforms2web.com, ALLOW-FROM https://test.vav.at, ALLOW-FROM https://test.vavpro.at, ALLOW-FROM https://meintest.vav.at- content-security-policy
frame-ancestors 'self' secure.vav.at abnahme.aforms2web.com vav-abnahme.aforms2web.com www.vav.at www.vavpro.at mein.vav.at beta.vav.at beta-mein.vav.at beta.vavpro.at test.vav.at test.vavpro.at meintest.vav.at www-admin.vav.at beta-admin.vav.at test-admin.vav.at; default-src 'unsafe-inline' 'self' https://cdnjs.cloudflare.com https://data.rtr.at https://cke4.ckeditor.com https://code.jquery.com https://secure.vav.at https://ws.vavonline.at https://vav-abnahme.aforms2web.com https://abnahme.aforms2web.com https://beta.vav.at https://beta-mein.vav.at https://beta.vavpro.at https://www.vavpro.at https://www.google.com https://www.google.es https://www.googletagmanager.com https://test-matomo.vav.at https://matomo.vav.at https://www.google-analytics.com https://region1.google-analytics.com https://www.vav.at https://stats.g.doubleclick.net https://region1.analytics.google.com https://www.ausgezeichnet.org data: https://maps.googleapis.com https://fonts.googleapis.com https://fonts.gstatic