realstep.it

.it crawl

First seen 2026-06-01 · Last seen 2026-06-01 · ok HTTP/1.1 200 3203 ms crawled 2026-06-01

IT · 86.107.32.150 · AS52030 Server Plan S.r.l.

Reputation 89/100 weak security headers dmarc monitor-only

Classifying

HTML metadata

Title
RealStep | Improve urban life
Language
en
Generator
Divi v.4.27.6
Canonical
https://realstep.it/en/
Translations
  • de
  • en
  • it
Feeds

Technology

Server
Apache
CMS
WordPress
jQuery
3.7.1
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (5)

  • fonts.googleapis.com×5
  • www.googletagmanager.com×2
  • app.legalblink.it×1
  • cdnjs.cloudflare.com×1
  • fonts.gstatic.com×1

Social

Contact

Email
Phone

DNS records live

NS
  • ns.kpnqwest.it
  • ns2.kpnqwest.it
MX
  • 5 realstep-it.mail.protection.outlook.com
Verified for
  • Microsoft 365

Email authentication partial

SPF
v=spf1 ip4:31.156.0.223 ip4:86.107.32.150 include:spf.protection.outlook.com ~all
softfail (~all)
DMARC
v=DMARC1;p=none;
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmZEbLeXauJSZHTXf+1aefpza+Bsji6xFD47zEXLKVDFBcqYO6dlF/KcrKmYHtVVJKy98iY3/b7VXJh3tYWD…
selectors probed

Certificate (current)

R13
from 2026-05-14 to 2026-08-12
Expires in 71 days

HTTP security headers

Header hygiene 35/100 Checked live page: https://realstep.it/en/

present
  • permissions-policy
findings
  • missing HSTS
  • missing Content Security Policy
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
Header values
permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")

Links to (2)

Linked from (1)