ticketline.pt
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Ads
-
- Meta Pixel
- Cookie consent
-
- Usercentrics
- Fonts
-
- Google Fonts
Third-party hosts loaded (9)
- www.googletagmanager.com×3
- web.cmp.usercentrics.eu×2
- www.facebook.com×2
- assets.web.sapo.io×1
- cdn-images.mailchimp.com×1
- connect.facebook.net×1
- fonts.googleapis.com×1
- thumbs.web.sapo.io×1
- tlpublicstorageprod.blob.core.windows.net×1
Social
Contact
DNS records live
- NS
-
- ns1.ptempresas.pt
- ns10.ptempresas.pt
- ns2.ptempresas.pt
- MX
-
- 0 ticketline-pt.mail.eo.outlook.com
- TXT
-
Show 6 TXT records
perun3698ms-domain-verification=7e283330-79b7-4808-9a3e-41817406d84eMS=D25BE16B09F1950BD5518328F90CB19278502F5CMS=ms88648286ms-domain-verification=0b435ae2-0043-43cd-80b6-d125bf56ba69ms-domain-verification=d3362486-fce5-49fb-beb8-867bcf870fe5
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net include:_spf.kmitd.com include:spf.mailjet.com include:sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-reports@ticketline.ptpolicy: none (monitoring only) - DKIM
-
- k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtvOnLb2jEDqZHGbY7grZZciVJtj+xdk37shj3uK5l6YX0ovsxMtaE5SR6rViBQsrRbyxqxHfGwNCrn/+7R… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqMQPgY88rnAvWYin+DoHOHdbw8Xq+vD9Q+bLfM1xgTHwF7hFzb7zPEns7A36kJEcaRP8BGx5RvXM0p5Iq/…
selectors probed - k1:
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- checked over plain HTTP
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin- permissions-policy
fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: api.ticketline.pt analytics.tiktok.com *.usercentrics.eu *.ticketline.sapo.pt google.com *.google.com *.google.pt googleads.g.doubleclick.net *.openstreetmap.org fonts.gstatic.com services.ticketline.pt *.sapo.io *.sapo.pt wa.sl.pt *.youtube.com *.vimeo.com *.google-analytics.com *.googleapis.com stats.g.doubleclick.net *.mailchimp.com ticketline.us14.list-manage.com pagamentosweb.reduniq.pt www.paypal.com www.wallet.pt wallet.pt idp.wallet.pt www.googletagmanager.com *.facebook.net www.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.ticketline.pt *.checkout.com *.equalweb.com *.googleadservices.com *.analytics.google.com tlpublicstorageprod.blob.core.windows.net; base-uri 'self';: script-src 'self' *.klarna.com *.checkout.com analytics.tiktok.com *.ticketline.pt *.ticketline.sapo.pt *.usercentrics.eu *.googletagmanager.com www.google-analytics.com;: script-src-elem 'self' 'unsafe-inline' *.googleadservices.com- strict-transport-security
max-age=31536000; includeSubDomains