agea.gov.it

.it crawl

First seen 2026-05-28 · Last seen 2026-05-31 · ok HTTP/1.1 200 1119 ms crawled 2026-05-30

IT · 4.232.112.78 · AS8075 Microsoft Corporation

Reputation 92/100 weak subdomain policy

Classifying

HTML metadata

Description
Agea, accanto all’agricoltore per lo sviluppo della filiera agricola. Ti diamo il benvenuto nel nuovo portale dell’Agenzia per le Erogazioni in Agricoltura.
Language
it

DNS records live

NS
  • dns.sian.it
  • dns2.fastweb.it
  • ns1a.btitalia.it
  • ns2a.btitalia.it
MX
  • 10 agea-gov-it.mail.protection.outlook.com
Verified for
  • Microsoft 365

Email authentication strong

SPF
v=spf1 ip4:20.16.3.161 ip4:93.32.50.20 ip4:4.232.144.23 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc-reports@agea.gov.it; ruf=mailto:dmarc-reports@agea.gov.it; pct=100; sp=none; aspf=s
policy: reject (enforced) · sp=none
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCbh1MSG6yJ1V3Af83VRU9ifb4ZawonEYxHlvPNtbBkM/OUqwVyKZiO2/z6FadJQ6aUNcuQSeBjXNgVTfmVny…
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNsJRb4qPWgKo95peLOEfTVC2sAj9gdDrpR++oZlsygyOrR9Zf3l9pKtFjPBm0qlYkM+pQulkKxqX2TtRlRN…
selectors probed

Certificate (current)

GeoTrust TLS RSA CA G1
from 2025-09-04 to 2026-09-18
Expires in 109 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.agea.gov.it/portale-agea/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' https://cdn.jsdelivr.net https://gstatic.com https://www.gstatic.com https://www.google.com https://matomo.agea.gov.it; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://gstatic.com https://www.gstatic.com; object-src 'none'; base-uri 'self'; form-action 'self' http: https:; frame-ancestors 'none'; frame-src 'self' http: https:; connect-src * data:; img-src 'self' * data: blob:; font-src 'self' data: https://fonts.gstatic.com;
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin-allow-popups
cross-origin-embedder-policy
unsafe-none
cross-origin-resource-policy
same-site

Linked from (3)