mandrarossa.it
HTML metadata
Technology
- Server
- immedia.net
- CMS
- Drupal
Third-party hosts loaded (3)
- mandrarossait.cdn-immedia.net×25
- app.vinhood.com×1
- embeds.accessiway.com×1
Social
Contact
DNS records live
- NS
-
- dns200.anycast.me
- ns200.anycast.me
- MX
-
- 1 relay.entermed.it
- 5 relay2.entermed.it
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 mx include:_spfpermissive.interhost.it a:relay2.entermed.it a:relay.entermed.it ip4:151.1.233.50 ip4:151.1.233.53 ip4:137.74.48.250 ~allsoftfail (~all) · multiple SPF records - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email;policy: none (monitoring only) - DKIM
-
- dkim:
v=DKIM1;k=rsa;t=s;s=email;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3v4s/GbNGJOLpFx7nm5f8EDMyJvgVGnFZpnBTXZJMU/af1OqZ3Dy+nAFbWukNhtbnfFU…
selectors probed - dkim:
Certificate (current)
E7
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self),midi=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=(self)- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: 'unsafe-eval' 'unsafe-inline'- strict-transport-security
max-age=63072000; includeSubDomains
Links to (4)
Linked from (2)
Use this data via API
Everything on this page for mandrarossa.it is available as JSON from the indexo.dev REST & MCP API.
curl "https://indexo.dev/api/v1/domains/mandrarossa.it" \ -H "X-API-Key: idx_..."