clei.it
HTML metadata
Technology
- Server
- Apache
- CMS
- Drupal
Social
Contact
- Phone
DNS records live
- NS
-
- dns.technorail.com
- dns2.technorail.com
- dns3.arubadns.net
- dns4.arubadns.cz
- MX
-
- 10 clei-it.mail.protection.outlook.com
- Verified for
-
- Brevo
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;rua=mailto:support-it@clei.it;pct=100;ruf=mailto:support-it@clei.it;fo=1;aspf=r;adkim=r;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbQ1AxNR84o6bsuziNkAxh4tq5hROlvGfcgylc4cIOUojZNj0sk5/yDMHablRnrUY9ieqaT+sMAVAs0wBS2c… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
E7
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self),midi=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=(self)- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: 'unsafe-eval' 'unsafe-inline'- strict-transport-security
max-age=63072000; includeSubDomains