unaparolaalgiorno.it
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Nuxt
- JS framework
- Nuxt, Vue
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (2)
- kit.fontawesome.com×1
- static.cloudflareinsights.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- lakas.ns.cloudflare.com
- sofia.ns.cloudflare.com
- MX
-
- 10 mail.unaparolaalgiorno.it
- Verified for
-
- Brave
- Meta
Email authentication weak
- SPF
- not published
- DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnRqdenCIFy2CVIYrXbM8W4RNx3SH2+AWKTTB2LnMBm5UgAH9+PyHAT1fhZ+tgpOSQK/N…
selectors probed - default:
Certificate (current)
WE1
Expires in 48 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self'; img-src 'self' * data:; media-src s3.eu-central-1.amazonaws.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' js.chargebee.com upag.chargebee.com fonts.googleapis.com unaparolaalgiorno.it; script-src 'self' 'self' cdn.unaparolaalgiorno.it *.upag.it 'unsafe-inline' 'unsafe-eval' unaparolaalgiorno.it polyfill.io sentry.io o411862.ingest.sentry.io *.sentry-cdn.com *.fontawesome.com unpkg.com cdn.jsdelivr.net static.cloudflareinsights.com *.cloudflare.com connect.facebook.net stats.g.doubleclick.net fonts.gstatic.com cdn.ampproject.org js.chargebee.com *.cloudflarestream.com; connect-src unaparolaalgiorno.it v3.unaparolaalgiorno.it cdn.unaparolaalgiorno.it *.upag.it sentry.io *.fontawesome.com unpkg.com o411862.ingest.sentry.io stats.g.doubleclick.net s3.eu-central-1.amazonaws.com connect.facebook.net cdn.ampproject.org *.ampproject.net adservice.google.com pagead2.googlesyndication.com; form-action 'self'; frame-ancestors 'none'; font-src 'self' unaparolaa- strict-transport-security
max-age=2592000; includeSubDomains; preload