nevasgr.com

.com crawl

First seen 2026-05-26 · Last seen 2026-05-30 · ok HTTP/1.1 200 5775 ms crawled 2026-05-30

IT · 193.41.198.203 · AS20942 Intesa Sanpaolo S.p.A.

Reputation 100/100

Classifying

HTML metadata

Title
Neva SGR - Home Page
Language
en

Technology

CMS
WordPress
Social widgets
  • YouTube Embed

Third-party hosts loaded (2)

  • www.youtube.com×24
  • media.licdn.com×1

Social

Contact

Email
Phone

Registration

Registrar
Tucows Domains Inc.
Created
2019-05-19
Expires
2027-05-19 352 days left
Updated
2026-04-20
Name servers
  • a1-148.akam.net
  • a7-64.akam.net
  • a9-64.akam.net
  • ns1.intesasanpaolo.com
  • ns2.intesasanpaolo.com
  • ns3.intesasanpaolo.com

DNS records live

NS
  • a1-148.akam.net
  • a7-64.akam.net
  • a9-64.akam.net
  • ns1.intesasanpaolo.com
  • ns2.intesasanpaolo.com
  • ns3.intesasanpaolo.com
MX
  • 10 mail1.intesasanpaolo.com
  • 10 mail2.intesasanpaolo.com
TXT
  • m6P92ryx6jjKNmMQ9L+YRmtvy3J5i31OQGvhh2KNlnk=
Verified for
  • GlobalSign
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:spf.intesasanpaolo.com include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:intesa-sanpaolo@rua.dmp.cisco.com; ruf=mailto:intesa-sanpaolo@ruf.dmp.cisco.com
policy: reject (enforced)
DKIM
  • dkim: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvDuhX8vEQYkVWphEfGGbOk9abO83G7I+Lnh+HWVmms4QxlUS9/5GVHSU9DhuwKUMRPgVnrlRjcl7j/…
selectors probed

Certificate (current)

GlobalSign RSA OV SSL CA 2018
from 2025-05-19 to 2026-06-20
Expires in 19 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.nevasgr.com/content/neva/en.html

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
content-security-policy
default-src 'self' *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' *; img-src 'self' data: *; connect-src 'self' *; font-src 'self' data: *; frame-src 'self' *; frame-ancestors 'self' *; upgrade-insecure-requests;
strict-transport-security
max-age=31536000; includeSubDomains

Links to (50)

Linked from (2)