segnalazioniwistleblowing.it
HTML metadata
Technology
- Server
- Apache
- jQuery
- 3.4.1 known XSS (<3.5)
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- code.jquery.com×1
- fonts.googleapis.com×1
DNS records live
- NS
-
- authns0.xtsystem.it
- authns1.xtsystem.it
- authns2.xtsystem.it
- authns3.xtsystem.net
- MX
-
- 20 avas03.priv.cloud.xtsystem.it
Email authentication partial
- SPF
-
v=spf1 mx a include:_spf.xtsystem.it -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@xtsystem.it; ruf=mailto:dmarc@xtsystem.it; fo=1policy: none (monitoring only) - DKIM
-
- dkim:
v=DKIM1;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrh8qXwIrLgBKtGlFfWgBZqc2Nj1D8kmH/PMgMF/W+pKxmoEsmBbDuzESr1JKPoSrf7gDIFwsJ5JatWriZPspQY7…
selectors probed - dkim:
Certificate (current) wrong cert
R12
Expires in 38 days
HTTP security headers
- findings
-
- checked over plain HTTP
- missing Content Security Policy
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy