stral.it
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Iubenda
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- cdn.iubenda.com×2
- ct.pinterest.com×1
- fonts.googleapis.com×1
- px.ads.linkedin.com×1
- www.facebook.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.dnsitalia.net
- ns2.dnsitalia.net
- nsct.dnsitalia.net
- nsrm.dnsitalia.net
- MX
-
- 5 stral-it.mail.protection.outlook.com
- TXT
-
00D5J000000EeMN=1TBSW00000000b7pardot860283=36d3815a218c485806a009db84d2a02846247361f58c4cf4028c0d2aa8fbad09
Email authentication strong
- SPF
-
v=spf1 ip4:149.202.52.140 a:av.palazzoli.it a:pmail.palazzoli.it include:servers.mcsv.net include:et._spf.pardot.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc@stral.it; aspf=rpolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDc73k1P2nM3s9cUg+7GQolEv6PTL/KxSgJtcVGMOw1Hv6H8L7pN9V2ncj0sFijQ87h6FF8Q+OC2b5VvjIm7V… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7Es267v7FWDkWIzMmRi8RVp/rBpHS2/7kZTDwNVPoWqTP12aJpIHdctWEwLvjGI365ZiOA8ux5f1Cz0sW1W…
selectors probed - selector1:
Certificate (current)
R12
Expires in 80 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com *.facebook.net *.google.com *.googleapis.com *.googletagmanager.com *.googleadservices.com *.gstatic.com *.iubenda.com *.fontawesome.com *.google-analytics.com *.jquery.com *.bootstrapcdn.com cdnjs.cloudflare.com *.g.doubleclick.net snap.licdn.com s.pinimg.com; object-src 'self' blob:; style-src 'self' 'unsafe-inline' *.googleapis.com *.jquery.com *.fontawesome.com *.bootstrapcdn.com cdnjs.cloudflare.com; img-src 'self' data: blob: *.facebook.com *.palazzoli.com *.googlesyndication.com *.gstatic.com *.google-analytics.com *.googletagmanager.com *.googleapis.com *.google.com *.google.it *.g.doubleclick.net *.jquery.com *.iubenda.com px.ads.linkedin.com ct.pinterest.com; frame-src 'self' *.hotjar.com *.facebook.com *.google.com *.iubenda.com *.youtube-nocookie.com ct.pinterest.com; font-src 'self' data: *.gstatic.com *.fontawesome.com *.bootstrapcdn.com; conne
Links to (7)
- facebook.com×1
- google.it×1
- instagram.com×1
- iubenda.com×1
- linkedin.com×1
- pinterest.it×1
- youtube.com×1