imiscoe.org
HTML metadata
Technology
- Server
- Apache
- CMS
- Joomla
- Fonts
-
- Google Fonts
Third-party hosts loaded (1)
- fonts.googleapis.com×1
Social
Contact
DNS records live
- NS
-
- ns1.greenhost.nl
- ns2.greenhost.net
- ns3.greenhost.nl
- MX
-
- 10 mx1.greenhost.nl
- 10 mx2.greenhost.nl
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 a mx include:spf.greenhost.nl -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; rua=mailto:re+bwe5xnmvmzn@dmarc.postmarkapp.com; sp=none; aspf=r;policy: none (monitoring only) · sp=none - DKIM
-
- default:
v=DKIM1; k=rsa; s=email; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjgpuoCE6LQeu4EjlRiFR8GTyIICw3cmrf1A8gSK+5582400gvpcosmFSI0F5mydmZ/2cwKhwfv… - mail:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3XbjmgH8Sz/xT6rsN/ZNuZDkY/LVe0w63PyIgPIJzYcwz2TosHNykpNhOz5xQW+3FlesOhdeLzgRuLhuzBGJSGHi0C…
selectors probed - default:
Certificate (current)
E7
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN, sameorigin- permissions-policy
geolocation=(); midi=();notifications=();push=();sync-xhr=();accelerometer=(); gyroscope=(); magnetometer=(); payment=(); camera=(); microphone=();usb=(); xr=();speaker=(self);vibrate=();fullscreen=(self);- x-content-type-options
nosniff- content-security-policy
default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https: data: ; frame-src 'self' https://*.soundcloud.com https://www.youtube-nocookie.com https://*.youtube.com https://www.google.com; frame-ancestors 'self'- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin
Links to (5)
Linked from (1)
- fieri.it×1