hatudo.pt
HTML metadata
Technology
- CDN
- Cloudflare
- jQuery
- 2.1.4 known XSS (<3.5)
- Stack
- PHP
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- dotec.pt×1
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- dahlia.ns.cloudflare.com
- luke.ns.cloudflare.com
- MX
-
- 0 mail.hatudo.pt
Email authentication partial
- SPF
-
v=spf1 a mx ip4:94.46.13.61 ip4:144.76.114.60 include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; fo=1; rua=mailto:dmarc@hatudo.pt; ruf=mailto:dmarc@hatudo.ptpolicy: none (monitoring only) - DKIM
-
- dkim:
v=DKIM1;k=rsa;t=s;s=email;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAr0YN1zw8jBeA5uSh77WEEpR2DTKmwVW/4FdMgGhX77YO7r3SNqlMnFRRNazm4HmpzOPs…
selectors probed - dkim:
Certificate (current)
WE1
Expires in 48 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src https: data: 'unsafe-inline' 'unsafe-eval'- strict-transport-security
max-age=15552000; preload