camigliano.it
HTML metadata
Technology
- Server
- Apache
- jQuery
- 1.12.3 known XSS (<3.5)
- Stack
- PHP
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- cdn.tnx.it×21
- www.facebook.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.tnx.it
- ns2.tnx.it
- ns3.tnx.it
- MX
-
Show 7 MX records
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- 30 aspmx4.googlemail.com
- 30 aspmx5.googlemail.com
Email authentication strong
- SPF
-
v=spf1 mx a include:_spf.google.com include:_spf.tnx.it ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; sp=quarantinepolicy: quarantine · sp=quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8LPyJX6+xaT0pg8hEgtVen7UycpqiFKoTlPj7NiUQtJSwSGeIJa1zyYZ3k3cpA+eAKNQI+TvhiHB0jvmd5d… - mail:
v=DKIM1; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDHGsvvk5Ylplb7tZu40Ng6owUsWmA63G6O15QMylvqydt7uuDgUxgvv3Hjl/FndNedqOy7eXjfYRvPo…
selectors probed - google:
Certificate (current)
R12
Expires in 81 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.tnx.it *.camigliano.it maps.googleapis.com/ ssl.google-analytics.com www.google-analytics.com www.googletagmanager.com/gtag/js googleads.g.doubleclick.net td.doubleclick.net www.googletagmanager.com/debug/; frame-src 'self' maps.googleapis.com/ storage.googleapis.com/ www.youtube-nocookie.com/ td.doubleclick.net www.googletagmanager.com/;
Links to (4)
- youtube.com×1
- tnx.it×1
- instagram.com×1
- facebook.com×1