battistolli.it
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- jQuery
- 2.2.4 known XSS (<3.5)
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Cookie consent
-
- Iubenda
Third-party hosts loaded (7)
- cdnjs.cloudflare.com×5
- cdn.jsdelivr.net×3
- code.jquery.com×3
- embeds.iubenda.com×1
- gmpg.org×1
- static.cloudflareinsights.com×1
- www.googletagmanager.com×1
Contact
DNS records live
- NS
-
- kai.ns.cloudflare.com
- penny.ns.cloudflare.com
- MX
-
- 0 battistolli-it.mail.protection.outlook.com
- TXT
-
have-i-been-pwned-verification=957a36d68cc39b2b2aacec50e073f024nMT7r0jiYV/JvYqh4Y4Uxj0R2GT3tPlq0ooPTRP/Em18ozM4o/qKu3XPx/6UgZc+LCDzM24IbWtbfi1JsbIuPA==
- Verified for
-
- Anthropic
- Microsoft 365
- Zoho
Email authentication weak
- SPF
-
v=spf1 mx ip4:54.36.197.97 ip4:51.38.16.48/30 ip4:51.255.146.80/30 ip4:212.146.212.74 ip4:2.228.4.1 include:spf.protection.outlook.com include:eu.transmail.net include:one.zoho.eu include:spf.zoho.eu include:spf-de.emailsignatures365.com include:_spf_eucentral1.prod.hydra.sophos.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDaaMEpW/WsVcVsZQlekFP1VIFz7DKvnPveMKDAE6dXj7qbPeEB5uD16fcqe+L4sZJ500oFmVE3j9JVfhzRGD…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 40 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- weak frame protection
- weak content type protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, sameorigin- permissions-policy
geolocation=(), microphone=(), camera=(), payment=()- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' https: data:; img-src 'self' https: data:; media-src 'self' https: data: blob:; frame-src 'self' https:; connect-src 'self' https:; object-src 'none'; frame-ancestors 'self';- strict-transport-security
max-age=63072000; includeSubDomains; preload