welslinien.at

.at crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 1116 ms crawled 2026-05-30

AT · 80.243.171.226 · AS21013 eww ag

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Wels Linien
Description
Öffentlicher Nahverkehr in Wels & Umgebung. ➤ Wir bringen unsere Fahrgäste an ihr Ziel.
Language
de
Canonical
https://www.welslinien.at/

Open Graph

url
https://www.welslinien.at/
title
Wels Linien
locale
de-DE
description
Öffentlicher Nahverkehr in Wels & Umgebung. ➤ Wir bringen unsere Fahrgäste an ihr Ziel.

Technology

Server
Apache
PHP
8.3.30 security-only

Third-party hosts loaded (1)

  • verkehrsauskunft.ooevv.at×1

Social

Contact

Phone

DNS records live

NS
  • dns3.itandtel.at
  • dns4.itandtel.at
  • dns5.itandtel.at
  • dns6.itandtel.at
MX
  • 5 welslinien-at.mail.protection.outlook.com
Verified for
  • Apple
  • Microsoft 365
  • TeamViewer

Email authentication partial

SPF
v=spf1 mx a:mail.brain-behind.com ip4:185.160.253.233 ip4:77.235.45.148 ip4:80.243.168.57 ip4:78.137.112.226 ip4:80.243.160.141 include:_spf.itandtel.at include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:subsit@eww.at
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeL7fvhB++GwDRgCK+rFEpz01NFtJ2evOcJXyKDpOrAiSrYIWFy5P6t4UUVAilVyToJML3IsXtS4iu+a86oI…
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7aIcD1JYsz3eXuD1z8v5JH8urzhdKmgM3/EtPL64ugX+1ZAx5rflXPZL/mHwFFstAs09jrKnNFF4UGpKOHn…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA DV R36
from 2025-11-13 to 2026-12-08
Expires in 190 days

HTTP security headers

Header hygiene 60/100 Checked live page: https://www.welslinien.at/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
frame-ancestors 'self'; default-src 'self' data: *.acsbapp.com *.googleapis.com *.ggpht.com *.digiaccess.org *.doubleclick.net *.eww.at assets.sendinblue.com assets.brevo.com *.ooevv.at *.haf.as *.sibforms.com; img-src 'self' data: *.eww.at *.googleapis.com *.ggpht.com *.ooevv.at; frame-src 'self' *.vimeo.com *.youtube-nocookie.com *.youtube.com *.google.com *.ggpht.com *.googlevideo.com forms.websms.com *.eww.at map.chge.at eww.appointlet.com solarrechner.eturnity.io *.office365.com eww-b2b.appointlet.com app.cituro.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.gstatic.com *.acsbapp.com *.googleapis.com *.digiaccess.org *.google.com *.eww.at sibforms.com *.ooevv.at; style-src 'self' 'unsafe-inline' *.eww.at *.gstatic.com *.googleapis.com sibforms.com *.ooevv.at

Links to (3)

Linked from (1)