odcec.pn.it
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- jQuery
- 3.7.1
Third-party hosts loaded (2)
- bnr.elmobot.eu×1
- hcaptcha.com×1
Contact
- Phone
DNS records live
- NS
-
- ns1.dnsitalia.net
- ns2.dnsitalia.net
- nsct.dnsitalia.net
- nsrm.dnsitalia.net
- MX
-
- 5 posta.sgiservizi.net
- TXT
-
_gjng9xp3st6qi6mi944vz470l7porc0_lg1tmewuhsb4s4lemqaxy9vb46p05toffe1c2cbeb3b431f9d64cbed9ccc3aab
- Verified for
-
- GlobalSign
Email authentication partial
- SPF
-
v=spf1 a:posta.sgiservizi.net include:spf.mailjet.com include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current) wrong cert
GlobalSign RSA OV SSL CA 2018
Expires in 312 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
base-uri 'self' 'unsafe-eval'; default-src 'self' www.google.com www.gstatic.com www.privacylab.it/elmo.php bnr.elmobot.eu cns.elmobot.eu hcaptcha.com js.hcaptcha.com newassets.hcaptcha.com app.satismeter.com www.odcecpadova.it www.ordcomm.it 'unsafe-inline' 'unsafe-eval' data:;;frame-ancestors 'self';font-src 'self' data: https://fonts.gstatic.com; frame-src https://www.google.com https://www.youtube.com/embed/ https://newassets.hcaptcha.com/ ;img-src data: 'self' https://secure.gravatar.com https://www.isiformazione.it https://s.w.org https://ps.w.org/- strict-transport-security
max-age=300