menarini.ch
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.register.it
- ns2.register.it
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 alt3.aspmx.l.google.com
- 30 alt4.aspmx.l.google.com
- TXT
-
Show 6 TXT records
jrlsgt4wf5xw2nvzc0dlx8p19gcbw6h8_640ex9ejmy7vojzrweq4gk2ohh5qmwb_m85kyx3scdgseu1lj7iy4kfjxu3bds8_ex8v819df6h68zg6ds72ed046lwibsjdpmn8vjzlz23b2fljdnncj2lfpwbcb09_jps5tnukvkk03d8fxifuwuy4xcjwf6o
- Verified for
-
- Adobe
- DocuSign
- Mailgun
- Microsoft 365
- OneTrust
- Smartsheet
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:spf.mailjet.com include:_spf.google.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 147 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'sha256-vQ2CoAt0FKlHSVrMMWjlM894KpJatQux0wtxg39JVXI=' 'sha256-KuouT3yFS2nUHYSNeIuMZCuXIlksjkrS9Gj3w3wF7IE=' 'sha256-3/mNUpqF9X/gMYE+bOG6g8d6I32wdYdWwWuAk90mPCM=' 'sha256-fwi2c6Q/IRv3As4uartpEdAzZWOkVvL1bJ1YAe9wUw8=' 'sha256-XRERY3SV7c1N3FwdWkNyhiKfZXfVVwRInOHszdmV0wE=' https://googletagmanager.com https://www.googletagmanager.com https://cdn.cookielaw.org https://google.com https://www.google.com https://www.google.gr https://www.google.fr https://www.google.co.uk https://www.google.it https://www.google.de https://www.google.pt https://www.google.es https://www.gstatic.com https://*.onetrust.com https://*.googleapis.com https://*.googlesyndication.com https://*.doubleclick.net https://connect.facebook.net https://snap.licdn.com https://player.vimeo.com https://cdn.plyr.io https://www.lusofarmaco.it.seg.js https://stage.lusofarmaco.it.seg.js https://dev.lusofarmaco.it.seg.js *.adobeaemcloud.com/; object-src 'none'; font-src 'self' data: https://fon- strict-transport-security
max-age=31536000; includeSubDomains; preload