vav.at

.at crawl

First seen 2026-05-30 · Last seen 2026-05-31 · ok HTTP/1.1 200 1589 ms crawled 2026-05-31

DE · 18.156.156.95 · AS16509 Amazon.com, Inc.

Reputation 92/100 spf without fallback

Classifying

HTML metadata

Title
VAV Versicherung ▶ Online berechnen & direkt abschließen!
Description
Die Vorteile Ihrer VAV Versicherung: Mit unseren Versicherungsrechnern die Prämie direkt auf der Website online berechnen und sofort abschließen.
Language
de

Technology

Server
nginx
jQuery
1.11 known XSS (<3.5)

Third-party hosts loaded (3)

  • download.digiaccess.org×1
  • siegel.ausgezeichnet.org×1
  • www.vavpro.at×1

Social

DNS records live

NS
  • ns-1359.awsdns-41.org
  • ns-1709.awsdns-21.co.uk
  • ns-385.awsdns-48.com
  • ns-520.awsdns-01.net
MX
  • 10 mail.vav.at
TXT
  • QuoVadis=700cf104-fcba-454e-b645-bd97dec23b4b
  • QuoVadis=f897e8f3-6ed5-42b7-b272-7082e341a50d
Verified for
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 redirect=23v7t4dy._spf._d.mim.ec
missing all
DMARC
v=DMARC1; p=quarantine; rua=mailto:718d4c8d4413921@rep.dmarcanalyzer.com; ruf=mailto:718d4c8d4413921@for.dmarcanalyzer.com; fo=1;
policy: quarantine
DKIM
no key found at common selectors

Certificate (current)

Amazon RSA 2048 M04
from 2025-09-29 to 2026-10-29
Expires in 150 days

HTTP security headers

Header hygiene 50/100 Checked live page: https://www.vav.at/privat

present
  • content-security-policy
  • x-frame-options
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • weak frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN, ALLOW-FROM https://beta.vav.at, ALLOW-FROM https://beta-mein.vav.at, ALLOW-FROM https://beta.vavpro.at, ALLOW-FROM https://secure.vav.at, ALLOW-FROM https://abnahme.aforms2web.com, ALLOW-FROM https://www.vav.at, ALLOW-FROM https://www.vavpro.at, ALLOW-FROM https://mein.vav.at, ALLOW-FROM https://vav-abnahme.aforms2web.com, ALLOW-FROM https://test.vav.at, ALLOW-FROM https://test.vavpro.at, ALLOW-FROM https://meintest.vav.at
content-security-policy
frame-ancestors 'self' secure.vav.at abnahme.aforms2web.com vav-abnahme.aforms2web.com www.vav.at www.vavpro.at mein.vav.at beta.vav.at beta-mein.vav.at beta.vavpro.at test.vav.at test.vavpro.at meintest.vav.at www-admin.vav.at beta-admin.vav.at test-admin.vav.at; default-src 'unsafe-inline' 'self' https://cdnjs.cloudflare.com https://data.rtr.at https://cke4.ckeditor.com https://code.jquery.com https://secure.vav.at https://ws.vavonline.at https://vav-abnahme.aforms2web.com https://abnahme.aforms2web.com https://beta.vav.at https://beta-mein.vav.at https://beta.vavpro.at https://www.vavpro.at https://www.google.com https://www.google.es https://www.googletagmanager.com https://test-matomo.vav.at https://matomo.vav.at https://www.google-analytics.com https://region1.google-analytics.com https://www.vav.at https://stats.g.doubleclick.net https://region1.analytics.google.com https://www.ausgezeichnet.org data: https://maps.googleapis.com https://fonts.googleapis.com https://fonts.gstatic

Links to (3)

Linked from (1)