menarini.at
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1.register.it
- ns2.register.it
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 alt3.aspmx.l.google.com
- 30 alt4.aspmx.l.google.com
- TXT
-
Show 7 TXT records
swisssign-check=mH-59tZStOTtf8wGrMSw3FSjsOEswisssign-check=97rrWb9WruVCG2h-PxQ_OQQg5toswisssign-check=aivRkaiw4p8qpo11dkJeBVYlvzcd2jm8jyy97ybmpj353cn98b6r9wy16sv_e540nyktl70a5bwxbcx4pf6a1befp46_m85kyx3scdgseu1lj7iy4kfjxu3bds8swisssign-check=5gwn1SHojvu47caVGK-5CQ4yoho
- Verified for
-
- DocuSign
- Mailgun
- Microsoft 365
- OneTrust
- Smartsheet
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:_spf.berlin-chemie.de include:_spf.google.com include:spf.mailjet.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantinepolicy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 146 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'sha256-KuouT3yFS2nUHYSNeIuMZCuXIlksjkrS9Gj3w3wF7IE=' 'sha256-3/mNUpqF9X/gMYE+bOG6g8d6I32wdYdWwWuAk90mPCM=' 'sha256-+Xw1amKC9z0zCdMoKJ6WO127UWyW2EhZf7O0bwv973s=' 'sha256-trRAWLvwH01kKKrYWqGc0Iheb03cwBCjXBhMDkits8A=' 'sha256-XRERY3SV7c1N3FwdWkNyhiKfZXfVVwRInOHszdmV0wE=' https://googletagmanager.com https://www.googletagmanager.com https://cdn.cookielaw.org https://google.com https://www.google.com https://www.google.gr https://www.google.fr https://www.google.co.uk https://www.google.it https://www.google.de https://www.google.pt https://www.google.es https://www.gstatic.com https://*.onetrust.com https://*.googleapis.com https://*.googlesyndication.com https://*.doubleclick.net https://connect.facebook.net https://snap.licdn.com https://player.vimeo.com https://cdn.plyr.io https://www.lusofarmaco.it.seg.js https://stage.lusofarmaco.it.seg.js https://dev.lusofarmaco.it.seg.js *.adobeaemcloud.com/; object-src 'none'; font-src 'self' data: https://fon- strict-transport-security
max-age=31536000; includeSubDomains; preload