aig.com.pt
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- Apache
Third-party hosts loaded (2)
- assets.adobedtm.com×1
- orgn-aigpt1.dmp.aig.com×1
Social
Contact
DNS records live
- NS
-
- ns1.bluecatdns.com
- ns1.bluecatdns.net
- ns1.bluecatdns.org
- TXT
-
Show 7 TXT records
9vq23jc1ttc3jd7sk4q37xc2gvj88yjc_4e4zjqngjid796c3z31cgs503fwgwdd_cetvewff8ja8gretv9564m4axu21fyqmykk32y3zm2jtrjf1s87tw063r1jgpxkz1fl8431gd4k1bl5lw83572rnrk451l216crwh1mbxmstyg3psxh0ckjmff1t0653j6hj7wdzbrz2895799q1n77947q98gj
Email authentication no MX
- SPF
-
v=spf1 include:%{d}.ac.spf-protect.agari.com exists:%{i}._i.%{d}._d.espf.agari.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:aig@rua.agari.com; ruf=mailto:aig@ruf.agari.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 205 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https: data: blob:; connect-src https: wss:;script-src https: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'unsafe-inline' blob:; frame-ancestors 'self'; upgrade-insecure-requests;- strict-transport-security
max-age=31536000;