scotturb.com

.com crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 1089 ms crawled 2026-05-30

US · 108.139.114.114 · AS16509 Amazon.com, Inc.

Reputation 89/100 weak security headers dmarc monitor-only

Classifying

HTML metadata

Title
Scotturb - Transporte oficial para os Palácios e Castelos de Sintra
Description
Scotturb - Transporte oficial para os principais palácios e monumentos de Sintra. Conectamos os principais palácios e castelos de Portugal com conforto e pontualidade.
Language
pt-PT

Open Graph

url
https://scotturb.pt
title
Scotturb - Transporte oficial para os Palácios e Castelos de Sintra
locale
pt_PT
description
Transporte oficial para os principais palácios e monumentos de Sintra. Conectamos os principais palácios e castelos de Portugal com conforto e pontualidade.

Technology

CDN
Amazon CloudFront
CMS
Next.js

Registration

Registrar
Register SPA
Created
2002-01-10
Expires
2027-01-10 223 days left
Updated
2026-01-11
Name servers
  • ns1.amenworld.com
  • ns2.amenworld.com

DNS records live

NS
  • ns1.amenworld.com
  • ns2.amenworld.com
MX
  • 0 scotturb-com.mail.protection.outlook.com
TXT
  • lovable_verify=b896686d13170373709aca0dcbac0ce4c0964e04007cfadc0c7355e54718d595
  • ca3-99bb4aac49704fb3a635f2128d7fa005
Verified for
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 a mx include:spf.protection.outlook.com include:spf.webapps.net include:mail.zendesk.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:carlos.sousa@scotturb.com; ruf=mailto:carlos.sousa@scotturb.com; fo=1; adkim=r; aspf=r; rf=afrf; sp=none
policy: none (monitoring only) · sp=none
DKIM
no key found at common selectors

Certificate (current)

Amazon RSA 2048 M04
from 2026-05-23 to 2026-12-07
Expires in 189 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://scotturb.com/

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src * data: blob: 'unsafe-inline'; script-src 'self' https://*.adyen.com https://*.ventrata.com https://checkout.ventrata.com https://assets.ventrata.com https://cdn.checkout.ventrata.com https://www.recaptcha.net https://*.googleapis.com https://*.gstatic.com *.google.com https://www.googletagmanager.com https://*.clarity.ms https://*.paypal.com https://pay.google.com https://* 'unsafe-inline' 'unsafe-eval' http://localhost:3000 https://*.gipsyy.com https://*.scotturb.com; connect-src 'self' https://*.adyen.com https://*.ventrata.com https://api.ventrata.com https://country.i18n.codes https://o290279.ingest.sentry.io https://*.googleapis.com https://*.gstatic.com *.google.com *.sintra-cms.gipsyy.com https://www.google-analytics.com https://*.clarity.ms https://eu.i.posthog.com https://*.paypal.com https://eu.i.posthog.com https://google.com https://pay.google.com https://* 'unsafe-inline' http://localhost:3000 https://*.gipsyy.com https://*.scotturb.com; frame-src https://*.ad

Links to (1)

Linked from (2)