purposia.eu
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress 7.0
Third-party hosts loaded (1)
- challenges.cloudflare.com×2
Social
Contact
- Phone
DNS records live
- NS
-
- ns.wedos.com
- ns.wedos.cz
- ns.wedos.eu
- ns.wedos.net
- MX
-
- 10 purposia-eu.mail.protection.outlook.com
- TXT
-
linkedin-site-verification=ef81494e-ae01-46b8-ad7a-8d2e7ab7fbf5"MS=ms20437250"
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.mandrillapp.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2tuvvRVUqhdJo+dgVz2XMgKE7wBA4r/xrl36DZ8UdkNVSyaOirncJxH/GN/3c6ZwXYetSsRtX7vueA… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
R12
Expires in 60 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
script-src 'self' 'unsafe-inline' https://challenges.cloudflare.com https://www.googletagmanager.com https://connect.facebook.net blob:; worker-src 'self' blob:; frame-src 'self' https://challenges.cloudflare.com https://www.youtube.com https://www.youtube-nocookie.com;