erasmusapp.eu
HTML metadata
Technology
- Server
- nginx
DNS records live
- NS
-
- sam.ns.cloudflare.com
- virginia.ns.cloudflare.com
- MX
-
- 10 aspmx.l.google.com
- Verified for
-
- HARICA
Email authentication weak
- SPF
-
v=spf1 a ip4:147.135.135.183 include:_spf.google.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsDWhuvCObSyV1QBayaaYXcJicYmYDIu64D2eIkdXMoBj1/2bx58tkkaKpoOeil2+deuEgMkDwSkFwN…
selectors probed - google:
Certificate (current)
GEANT TLS RSA 1
Expires in 188 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'sha256-UVP+12g7SegPCHIkwPwQ9OK7J6u2BlJsP24SMLKPe9M=' 'sha256-Vd5rp1WHyyJLMkjn3G1xqqu5MBprNrMY3+1rMYCPJd8='; style-src 'self' 'unsafe-inline'; frame-src www.youtube-nocookie.com; img-src 'self' data: *.ytimg.com gisco-services.ec.europa.eu housinganywhere.imgix.net storage.googleapis.com cdn.dovevivo.it i.ibb.co lodgerin-archives-production.s3.amazonaws.com lodgerin-production.s3.gra.io.cloud.ovh.net polimi365-my.sharepoint.com roomless-listing-images.s3.us-east-2.amazonaws.com s3-eu-west-1.amazonaws.com/house.italianway.production www.residenze.polimi.it www.homiii.com www.spotahome.com photos.spotahome.com home2.spotahome.com cdn-static-new.uniplaces.com static.pic.chez-nestor.com cellar-c2.services.clever-cloud.com/media.studapart.com *.housing.production.uni-foundation.eu *.housing.dev.uni-foundation.eu *.housing.uni-foundation.eu- strict-transport-security
max-age=63072000