iccreabanca.it
HTML metadata
Technology
- Server
- X
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×2
- fonts.gstatic.com×1
- static.publisher.iccrea.bcc.it×1
DNS records live
- NS
-
- gbidns01.bcc.it
- gbidns02.bcc.it
- MX
-
- 9 cust66335-1.in.mailcontrol.com
- TXT
-
Show 9 TXT records
I8dIXZdOIlkeJbXQWs8PN+iXe4GDsKTeNotNNn7ARe8=3l8jg73w3jx8jc02hqk6q6d12m6tsj1cI8dIXZdOIlkeJbXQWs8PN16lynnPdQJ31mR/1STuDtQ=phgchqbyd8wlmprv74dsnwlj3lbr12h1_qfs4p3y1quj3f3v32vydnpbrxxu77ewI8dIXZdOIlkeJbXQWs8PN+lM6d1MnKkesiTTml1MNOc=MS=ms83204210I8dIXZdOIlkeJbXQWs8PN7cgakBk4OfgqZ+fYEn9R3g=_kd2fcxm0p813gdwxzvi4pyld6us2ppe
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_rua@emaildefense.proofpoint.com, mailto:dmarc_rua@bccsi.bcc.it; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; pct=100; ri=86400; fo=1policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 12 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
- weak content type protection
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(),camera=(), display-capture=(), encrypted-media=(), fullscreen=(), gamepad=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(),sync-xhr=(self),usb=(), screen-wake-lock=(), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff, nosniff- content-security-policy
frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com;- strict-transport-security
max-age=63072000; includeSubDomains; preload