wienerborse.at
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Google AdSense
- Google Ads
- Google Ads (DoubleClick)
- Cookie consent
-
- Cookiebot
- Fonts
-
- Google Fonts
Third-party hosts loaded (17)
- www.googletagmanager.com×3
- ajax.googleapis.com×2
- consent.cookiebot.com×2
- mocafirst.at×2
- consentcdn.cookiebot.com×1
- download.digiaccess.org×1
- fonts.googleapis.com×1
- googleads.g.doubleclick.net×1
- pagead2.googlesyndication.com×1
- securepubads.g.doubleclick.net×1
- stats.g.doubleclick.net×1
- tpc.googlesyndication.com×1
- www.google-analytics.com×1
- www.google.com×1
- www.googleadservices.com×1
- www.googletagservices.com×1
- www.gstatic.com×1
Social
DNS records live
- NS
-
- ns.wbag.at
- ns1.f5clouddns.com
- ns2.f5clouddns.com
- MX
-
- 10 mx1.wbag.at
- 10 mx2.wbag.at
- TXT
-
Show 4 TXT records
MS=30125D2CDF39AA6A609A19C286E611F47E9042D4heyhack-verification=019a776b-48e8-72b7-b756-c662c215025cheyhack-verification=019a776d-ea64-78da-a040-8519efca57ecS35g8LRt+Eg9Fq8MLyYOx0xsCzuxeUxcXlY/ofa8v35vxqkg1OO9eL7bZYUEygakC95yDQGHSdPsMMfWGLsOmw==
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx include:spf.protection.outlook.com include:spf.brevo.com include:spf.mailjet.com ip4:213.164.9.17 ip4:213.164.9.18 ip4:213.32.173.95 ip4:217.11.193.39 ip4:217.11.193.159 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-reports-rua@wienerborse.at,mailto:dmarc_agg@vali.email;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDc5j2Bv5Zq1RQ4yjxvKReatUXPt/zFG7W9DI8Sp2NvER7NpSNS7dIPhYjKdTUg4BFXQfFuidUg2Z4MqyV163… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvGBnXsKMl3eWy+Sr+GXBHPo61xWXMUcPGBNmI3f12mg9BKGZnsR8eYiuT+R1vYAi5QUZK0nl+2zF0A… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - selector1:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 88 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'unsafe-inline' 'self' https:; child-src 'self'; connect-src 'self' https:; font-src 'self' fonts.gstatic.com; frame-src 'self' https:; img-src * data:; manifest-src 'self'; media-src 'self' https:; object-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' https:; style-src 'unsafe-inline' 'self' *.twitter.com *.twimg.com fonts.googleapis.com; worker-src 'self'; base-uri 'self'; form-action 'self' *.twitter.com papi.hobex.at; navigate-to 'self' https:- strict-transport-security
max-age=16070400; includeSubDomains
Links to (9)
- linkedin.com×1
- salesxp.com×1
- takeover.at×1
- tiktok.com×1
- x.com×1
- youtube.com×1
- deetail.at×1
- factset.com×1
- instagram.com×1