enegan.it
HTML metadata
Technology
- Server
- nginx
- JS framework
- Angular 13.3.12
Third-party hosts loaded (2)
- cse.google.com×1
- light.appgrade34.it×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns.tol.it
- dns2.tol.it
- MX
-
- 10 enegan.esvacloud.com
- 10 enegan2.esvacloud.com
- TXT
-
Show 9 TXT records
_yqb0g2krqecquazbwflrec9y4vrhdmxknsgd2z8035k0bcbch501dcmz4bm6mws0zbh8nbvrm14q36hdp48j86990zpzwgkamazonses:QspfxhrdtMdteUdBMH5gKXxyElcCOpIz9BZRe8TmMto=ms=ms69498930r3hee4gmb9tj8lgh0csda2dav1have-i-been-pwned-verification=dweb_jneywn9us4znrlzode9wb02qduo_sso_verification=SzygBhEHk2Yj1YmpfFfd19vFHB9ftKDaPf00Xh0WUn2exm9n8fKqIiCTLFSbuoOX_ussywf9tbkgx9wr3dj2uosdbjns4njn
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 include:m8k8eywsob.powerspf.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=none; rua=mailto:7j2elxub52@rua.powerdmarc.com; ruf=mailto:7j2elxub52@ruf.powerdmarc.com; pct=10; fo=1;policy: quarantine · pct=10 · sp=none - DKIM
-
- default:
v=DKIM1;k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD1uZxJkOqOPCC4YwWEyE0OwBSfGxWRXxvp624QX095CHB2305KB37r6INtIPLm817bUpmaSLvVq7miF5fmkqhz… - google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3DoabyuvaDi0I0n/FP1qLAaGHQgKw+nZbBxHpv8sT66yQBj5Xeb1JZBQX6A2Q62YE79z5qRQSUN1rW… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+UJGsmscHXH6x9aGKMfX6CeL3uMrFLsWRZPcJbl4r2m1kGneru27TumqNYu4RgPnNUr0PMhKT7ys21h1A7t…
selectors probed - default:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 111 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
img-src 'self' data: *.google.com *.google.it *.googleadservices.com https://www.google-analytics.com https://*.doubleclick.net https://www.googleapis.com https://*.appgrade34.it/ https://www.googletagmanager.com https://*.googleapis.com *.gstatic.com *.iubenda.com *.zopim.com *.zdassets.com *.linkedin.com *.bing.com *.clarity.ms *.facebook.com https://via.placeholder.com https://syndicatedsearch.goog https://*.adtrafficquality.google https://*.stape.pro https://stape.pro https://*.stape.io https://stape.io https://*.intervieweb.it https://light.appgrade34.it/ https://www.enegan.it/ https://www.enegan.it/;script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.iubenda.com https://*.googletagmanager.com https://*.google-analytics.com https://*.googleapis.com *.google.com *.google.it *.googleadservices.com https://stats.g.doubleclick.net *.licdn.com *.bing.com *.facebook.net *.doubleclick.net *.zopim.com *.zdassets.com *.clarity.ms *.facebook.com https://*.intervieweb.it https://www.gs- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin