danone.it
HTML metadata
Technology
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (2)
- cdn.tagcommander.com×1
- www.youtube.com×1
Social
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 10 margaux.fullsix.it
- 20 montrachet.fullsix.it
- TXT
-
bgb2t8593dy3ltx98l53g2f7hrx0h2wcgoogle-site-verification=V1UDsjqjyFyLMyu4VV2XItkDgZc03O9YEboodo3UIQU
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=*- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' *.algolia.io/ https://forms.office.com/ *.adobe.io/ *.mikmak.ai/ *.swaven.com/ *.aptaclub.com/ https://sibforms.com/ *.q4web.com/ *.adobe.com/ *.unpkg.com/ https://unpkg.com/aos@next/dist/aos.css https://unpkg.com/aos@next/dist/aos.js https://widgets.q4app.com/widgets/requireslib/pym.v1.min.js https://s.pinimg.com/ct/core.js/ *.jsdelivr.net/ *.algolia.net/ *.algolianet.com/ *.audioeye.com/ *.danonenorthamerica.com/ *.scene7.com/ *.adobeaemcloud.com/ *.digital4danone.com/ *.aemcs.digital4danone.com/ *.ylt.nl/ *.danone.id/ https://yourdriversfordanonebenelux.com/ *.weezevent.com/ *.snapchat.com/ *.mathtag.com/ *.clevy.io/ *.commandersact.com/ *.twimg.com/ *.twitter.com/ *.live2support.com/ *.lpsnmedia.net/ *.googletagmanager.com/ *.gstatic.com/ *.commander1.com/ *.bootstrapcdn.com/ *.tagcommander.com/ *.zencdn.net/ *.sharethis.com/ *.googleapis.com/ *.google.com/ 'unsafe-inline'; script-src 'self' *.algolia.io/ https://forms.office.com/ *.adobe.- strict-transport-security
max-age=31536000; includeSubDomains; preload