tovuti.io
HTML metadata
Technology
- Server
- Apache
- CMS
- Joomla
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- uploads-ssl.webflow.com×25
- tovutilms.com×13
- fonts.googleapis.com×6
- cdnjs.cloudflare.com×1
- code.jquery.com×1
- js.stripe.com×1
- www.tovutilms.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- bailey.ns.cloudflare.com
- ram.ns.cloudflare.com
- MX
-
- 0 smtp.secureserver.net
- 10 mailstore1.secureserver.net
- TXT
-
zoom-domain-verification = 52e056e6-4c35-11ee-be56-0242ac120002
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
- not published
- DMARC
-
v=DMARC1;p=quarantine;rua=mailto:dmarc@tovutiteam.com;ruf=mailto:dmarc@tovutiteam.com;rf=afrf;pct=100;adkim=r;ri=86400;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 167 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * 'self' 'unsafe-inline' data: gap: content: blob: mediastream:; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob:; connect-src *; font-src * data:; frame-src * blob: data:; media-src * blob: data:; object-src * blob:; child-src * blob: gap:; form-action *; frame-ancestors *; worker-src * blob:;- strict-transport-security
max-age=31536000; includeSubDomains