18tickets.it
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- www.google.com×1
Social
Contact
DNS records live
- NS
-
- gabe.ns.cloudflare.com
- mary.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=C0Yrg_keuv6L3AElKnqKgKUZVQ1FadIu8LNfLd9JMAkgoogle-site-verification=2y2m3JQeDDquGCBAWlO-hKOjivdFi00g17iDZHJ6I8wgoogle-site-verification=4RRwLVukL0QbxBH5IR3lSp1CX-mevtcp667LtsLBo3w
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com ip4:81.201.124.0/28 ip4:15.161.194.80/32 ip4:18.102.220.254/32 ip4:2.229.167.126/32 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:notifications@18months.itpolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAy9aqsoULjPVMBWJU/gRmnhGVb8io1o5PwX0BF0HCGSod6zcEG2fTJ7yZCsmIe4cR9Xw81leNxG+KzD…
selectors probed - google:
Certificate (current)
WE1
Expires in 35 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' *.localhost.test *.pages.dev *.tickettando.it tickettando.it *.casacinemanapoli.it;- strict-transport-security
max-age=31536000