itacalibri.it
HTML metadata
Technology
- ASP.NET
- 4.0.30319
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- fonts.googleapis.com×3
- stackpath.bootstrapcdn.com×2
- eu1-config.doofinder.com×1
- www.gestpay.it×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns1.register.it
- ns2.register.it
- MX
-
- 10 mx1.safetycloud.it
- 20 mx2.safetycloud.it
- 30 mx3.safetycloud.it
- TXT
-
MS=BEB75392EA75B02DCF9063EC5E56E70990375EF3
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:176.221.48.192 ip4:176.221.48.198 ip4:176.221.48.179 include:spf.safetycloud.it include:musvc.com include:spf.webapps.net ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 65 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- content-security-policy
default-src 'self' 'unsafe-eval' https://static.zdassets.com https://ekr.zdassets.com https://*.zendesk.com wss://*.zendesk.com wss://*.zopim.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googleadservices.com https://googleads.g.doubleclick.net http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://v2.zopim.com https://connect.facebook.net https://eu1-config.doofinder.com/ https://eu1-search.doofinder.com https://cdn.doofinder.com https://stackpath.bootstrapcdn.com https://fonts.googleapis.com https://sandbox.gestpay.net https://ecomm.sella.it https://www.gestpay.it https://static.zdassets.com https://ekr.zdassets.com https://*.zendesk.com wss://*.zendesk.com wss://*.zopim.com https://www.paypal.com https://www.gstatic.com https://*.iubenda.com; connect-src 'self' wss://eu1-layer.doofind