iparque.pt
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
DNS records live
- NS
-
- destiny.ns.cloudflare.com
- skip.ns.cloudflare.com
- MX
-
- 10 mail.iparque.pt
- TXT
-
pardot969993=33c234cf3eba9487aaea43c2c9c7f67ded6ba10700eaf70fc169f330004b7c55
Email authentication strong
- SPF
-
v=spf1 a mx ip4:194.38.136.156 ip4:62.28.56.161 ip4:62.28.56.174 ip4:193.43.40.177 ip4:193.43.40.183 ip4:193.43.40.184 include:_spf.salesforce.com include:spf.mailjet.com -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;pct=100;rua=mailto:sysadmin_dmarc_reports_b3gt7@iparque.pt; sp=none; aspf=s; adkim=s;policy: reject (enforced) · sp=none - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq19RAEReZany30BbGIqyOeXnx4pJI9qtt5ZH5O4Qs4OisOq6Uy2WobSj0pkxj24pp6J7WjrLjJuXww…
selectors probed - default:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 151 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' *.iparque.pt/ www.iparque.pt/cpostal/ connect.facebook.net www.google.com/recaptcha/ www.gstatic.com/recaptcha/api2/ *.googleapis.com/ www.gstatic.com/charts/ www.gstatic.com/recaptcha/ developers.google.com/maps/ www.google.com/jsapi www.google.com/uds/ *.bootstrapcdn.com/ *.cloudflare.com/ www.google-analytics.com/ pi.pardot.com cdn.pardot.com info.acin.pt https://*.googletagmanager.com localhost:8081; style-src 'self' 'unsafe-inline' *.googleapis.com/ www.gstatic.com/charts/ www.google.com/uds/ *.bootstrapcdn.com/ *.cloudflare.com/ localhost:8081; font-src 'self' fonts.gstatic.com/ *.bootstrapcdn.com/ localhost:8081; frame-src 'self' staticxx.facebook.com/connect/ www.google.com/recaptcha/api2/ https://www.youtube-nocookie.com/ www.googletagmanager.com; img-src 'self' https://i.ytimg.com www.facebook.com maps.google.com/mapfiles/ maps.gstatic.com/mapfiles/ *.ggpht.com/ *.googleapis.com/ *.google.com- strict-transport-security
max-age=63072000; includeSubDomains; preload;
Linked from (4)
- taxaturismo.pt×1
- lcglobal.pt×1
- acin.pt×1
- datarede.pt×1