idok.pt
HTML metadata
Technology
- Stack
- Laravel
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×3
- www.googletagmanager.com×1
DNS records live
- NS
-
- destiny.ns.cloudflare.com
- skip.ns.cloudflare.com
- MX
-
- 10 mail.idok.pt
- TXT
-
pardot969993=e03afcc108504224167ca6944370266351a1bde52980d42fa36bbbe20f5e76a8
Email authentication strong
- SPF
-
v=spf1 a mx ip4:62.28.56.188 ip4:62.28.56.161 ip4:62.28.56.174 ip4:193.43.40.177 ip4:193.43.40.183 ip4:193.43.40.184 include:_spf.salesforce.com include:spf.mailjet.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:sysadmin_dmarc_reports_t9pr1@idok.pt; sp=none; aspf=s; adkim=s;policy: reject (enforced) · sp=none - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2rpSqORgJEiYuw2nroSRR23bcLAZ1dDGYEdHLB2TDRk3dsmHhEqkZ6WwjEc0OS5A8MNy3uza/zjifk…
selectors probed - default:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 131 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), midi=(), sync-xhr=(self), microphone=(), camera=(), magnetometer=(), gyroscope=(), fullscreen=(self), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' fonts.googleapis.com; connect-src 'self' *.google-analytics.com https://www.googletagmanager.com https://pagead2.googlesyndication.com http://sentry.acin.pt:* http://localhost:* ws://localhost:* www.google.com www.google.pt https://google.com/pagead/ https://tagassistant.google.com wss://tagassistant.google.com; script-src 'self' www.google.com www.gstatic.com *.google-analytics.com http://sentry.acin.pt:* *.googletagmanager.com *.acin.pt https://tagassistant.google.com; media-src 'self' youtube.com; frame-src 'self' data: www.google.com www.youtube.com *.acin.pt *.googletagmanager.com https://tagassistant.google.com; img-src 'self' blob: data: *.googletagmanager.com http://localhost:* *.google-analytics.com *.doubleclick.net *.googlesyndication.com *.google.com *.google.pt https://tagassistant.google.com; font-src 'self' data: fonts.gstatic.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com www.gstatic.com;- strict-transport-security
max-age=63072000; includeSubDomains; preload;