autotorino.it
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- res.cloudinary.com×245
- embed.typeform.com×1
- maps.google.com×1
- use.typekit.net×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns1.register.it
- ns2.register.it
- MX
-
- 10 autotorino-it.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
ztWzqlmPrfRyHyj+9EhToF/ee08dl2CwiV3Fa8uG5VFzh7+wvId7OgoU4QR8uCVkAbhVoek0y1NpOsPc42C+Hw==_qqr5wdrfjeuv604kr2ubnes30ng1rq5have-i-been-pwned-verification=83895e16ca047426abdc45cc6fc33eefhave-i-been-pwned-verification=dweb_cz803b138v2nkfqdevhd3lhl_c5bp7zxo2hdwquc378g8te6971f8zpd
- Verified for
-
- 1Password
- Meta
- Microsoft 365
- Perplexity
- TeamViewer
Email authentication strong
- SPF
-
v=spf1 ip4:185.132.171.134 include:spf.eu.exclaimer.net include:spf.protection.outlook.com include:docebosaas.com include:u826348.wl.sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100;policy: quarantine - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCNttaydOFArzaWjC/G/NoDquyWA7rLJxtH6viLX8WFv9pw268BlsoRnLBt0L5OrpxlYDA0ArUbXsW/Vd0TE… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0GLMlv8ngr1ILjfS2seQi6FX2QTNESRrrKujNz193mxG1eBp8EqismSNJrLts15FGs5/ex5jBQLhDR… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAksIQEDdJSy4BqAL8FURe85ecT60dptKBG7p2HJbOh7Akjf0Bffp2oR6csTLiutaV0nDSYLeaaKpQoAFlBy… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDo43AjV0MDYw4wq83uO1eSgkCPyHdzfluG3TzygIN5sipKUVxOVyD/vjnGs6UQIFQJsOBR90hhFJqgDc3tCXklEx…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 272 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.gstatic.com *.cloudinary.com *.acsbapp.com *.cloudflare.com *.googleapis.com *.autotorino.it https://fonts.gstatic.com *.typekit.net *.nimbata.com *.livechatinc.com https://www.clarity.ms *.clarity.ms *.optinmonster.com *.omappapi.com *.jotform.com *.jotfor.ms *.sentry-cdn.com *.jotformeu.com maxcdn.bootstrapcdn.com acsbapp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com cloudinary.com *.cloudinary.com *.autotorino.it https://0merchantacsstag.cardinalcommerce.com *.livechatinc.com *.jotform.com *.jotfor.ms *.sentry-cdn.com *.jotformeu.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo
Links to (7)
- youtube.com×1
- wa.me×1
- tiktok.com×1
- sharepoint.com×1
- linkedin.com×1
- instagram.com×1
- facebook.com×1