onaosi.it
HTML metadata
Technology
- Server
- Apache
- Stack
- Java
DNS records live
- NS
-
- ns2.leonet.it
- ns4.leonet.it
- ns6.leonet.it
- MX
-
- 1 mx-01-eu-central-1.prod.hydra.sophos.com
- 2 mx-02-eu-central-1.prod.hydra.sophos.com
- 5 mxbck.leonet.it
- TXT
-
Show 5 TXT records
4ru8oaujmfbg6kg2406in0druobgilfafds2l9241rcrbkkh3i1asophos-domain-verification=e9fbd704c2ed458d83d3df7bc206ebfcd1397c4fcmjg1efge4mpg3e10ohag4grrnsophos-domain-verification=9b0e4b879b2339ffe3bacbe91dca91a67a8afacdb2d82f7fab171443bf5f91d1
Email authentication weak
- SPF
-
v=spf1 mx ip4:93.39.84.200/29 ip4:93.43.110.188/30 include:t.contactlab.it include:_spf.prod.hydra.sophos.com include:_spf-legalmail.infocert.it -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 94 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://code.jquery.com https://maxcdn.bootstrapcdn.com https://ingestion.webanalytics.italia.it https://consent.cookiebot.com https://consentcdn.cookiebot.com https://js.hcaptcha.com/1/api.js?hl=it https://hcaptcha.com/1/api.js style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://maxcdn.bootstrapcdn.com; font-src 'self' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://maxcdn.bootstrapcdn.com; font-src 'self' https://fonts.googleapis.com/css2?family=Fira+Sans:wght@100;200;300;400;500;600;700;800;900; img-src 'self' data: http://www.onaosi.it https://www.onaosi.it https://imgsct.cookiebot.com https://ingestion.webanalytics.italia.it; object-src 'none'; base-uri 'self'; connect-src 'self' http://www.onaosi.it https://www.onaosi.it https://ingestion.webanalytics.italia.it https://consentcdn.cookie- strict-transport-security
max-age=31536000; includeSubDomains; preload