resaver.eu
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- cdn.jsdelivr.net×1
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns1135.papaki.gr
- ns2135.papaki.gr
- MX
-
- 10 resaver-eu.mail.protection.outlook.com
- TXT
-
MS=ms68217032
Email authentication strong
- SPF
-
v=spf1 +a +mx include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100 ; sp=none; ruf=mailto:no-reply@resaver.eu; fo=1:d:spolicy: reject (enforced) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2Z021X9XKOQKiPYYFtlVKDIZajd+Lpwz9d5p2fWGGQjbVI6p6VPcb/2CF0Jpm/pXr2F9IJwyD57Fp/… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsVgHlAjPvZCfbnF2De5qgGvnSSozqzGkURiguu8FNSUG1miUQdRdGZ2f5ROn+jnRckMuVuY7SSq/sO…
selectors probed - selector1:
Certificate (current)
R13
Expires in 37 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.resaver.eu; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.resaver.eu https://www.googletagmanager.com https://www.google-analytics.com/ https://cdn.jsdelivr.net/npm/iconify-icon@1.0.8/dist/iconify-icon.min.js https://cdn.stat-track.com/statics/moosend-tracking.min.js https://cdn.designer-images.com https://cdn-editor.moosend.com https://cdn.jsdelivr.net/npm/js-cookie@3.0.5/dist/js.cookie.min.js; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://fonts.gstatic.com https://cdn-editor.moosend.com/ https://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/font-awesome.min.css; img-src 'self' *.resaver.eu data: www.googletagmanager.com https://www.google-analytics.com/ https://moosendimages.imgix.net https://cdn.designer-images.com; frame-src www.youtube-nocookie.com youtu.be www.youtube.com; frame-ancestors 'none'; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; connect-src 'self' www.googleapis.com www.google- strict-transport-security
max-age=31536000