arcassicura.it
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- JS framework
- Next.js
Social
Contact
DNS records live
- NS
-
- ns1.agsmtel.it
- ns2.agsmtel.it
- nsa2.agsmtel.it
- MX
-
- 10 mx1.hc2103-18.eu.iphmx.com
- 10 mx2.hc2103-18.eu.iphmx.com
Email authentication partial
- SPF
-
v=spf1 exists:%{i}.spf.hc2103-18.eu.iphmx.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarcreport@arcassicura.it; ruf=mailto:dmarcreport@arcassicura.it; fo=1;policy: none (monitoring only) - DKIM
-
- dkim:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuNEwSIFV9w3O+UUbILNKjPn02Y02sQyTjuOfIe8qTl3nS8rUzpwEJ8bNO5qW4lBS5n9bX6ap421IFAkBs6i25…
selectors probed - dkim:
Certificate (current)
R13
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; child-src 'none'; connect-src 'self' https://www.arcassicura.it https://api.sitewww.arcassicura.it https://api-arca.sitewww.arcassicura.it *.googleapis.com https://arca.piwik.pro https://arca.containers.piwik.pro https://m.arcassicura.it http://m.arcassicura.it https://consentcdn.cookiebot.com https://consent.cookiebot.com https://consentcdn.cookiebot.eu https://consent.cookiebot.eu; default-src 'self'; font-src 'self' data: *.gstatic.com https://arca.containers.piwik.pro; form-action 'self' https://my.arcassicura.it; frame-ancestors 'none'; frame-src *.google.com www.youtube-nocookie.com https://consentcdn.cookiebot.com; img-src 'self' data: static.sitewww.arcassicura.it static.arcavita.caffeina.host static.develop.arca-assicura-website-cms.n3.caffeina.host https://m.arcassicura.it http://m.arcassicura.it *.googleapis.com *.gstatic.com https://arca.containers.piwik.pro https://imgsct.cookiebot.com; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src '- strict-transport-security
max-age=31536000; includeSubDomains
Links to (4)
Linked from (2)
- bpf.it×1
- unipol.com×1