valeo.it
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- app.greenweb.org×1
- mailer.valeo.email×1
- use.typekit.net×1
- widget.webability.io×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.register.it
- ns2.register.it
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
google-site-verification=takb27JiKKaQe6p1MDHJRytLoacYm7jl5Ov6jEyzVDsMS=D3646643E7D6045F8D4288C9096C068E1B36512B
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:musvc.com ip4:94.237.89.80 include:mxsspf.sendpulse.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; aspf=s; rua=mailto:dmarc-reports@valeo.itpolicy: reject (enforced) - DKIM
-
- default:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDgUWs1WWWILso3lvP5vwP5WTYTWC3Z7QkDMchWva7qgDnE+vyQhYtLntsulVHYVSZphRR3yblbNZjKR9d0lDjs1ylu0… - google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAisNg7AJs2ywUk1uY9+zL7QZqsAmH/OUXUN6TIYwoDrJ/J3ftpjLB80i+n3N7wWs1StzPNauQDCG0S7…
selectors probed - default:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 150 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self';connect-src 'self' *.google-analytics.com *.googlesyndication.com *.googleapis.com *.cookiehub.net *.google.com stats.g.doubleclick.net cdn.linkedin.oribi.io googleads.g.doubleclick.net mailer.valeo.email https://px.ads.linkedin.com https://v.clarity.ms/collect https://w.clarity.ms/collect https://api.webability.io/graphql https://cookiehub.net/client/b92fb30c/it.json *.webability.io *.googleadservices.com *.google.it *.clarity.ms;font-src 'self' *.gstatic.com *.typekit.net;frame-src 'self' *.facebook.com https://td.doubleclick.net/ https://www.googletagmanager.com/;img-src 'self' data: *.google-analytics.com *.googletagmanager.com *.google.com *.google.it *.googleapis.com googleads.g.doubleclick.net maps.gstatic.com lh3.ggpht.com px.ads.linkedin.com *.facebook.com *.clarity.ms *.bing.com *.greenweb.org *.nl-ams.scw.cloud;script-src-elem 'self' 'unsafe-inline' *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.googleapis.com https://*.googleapis.c- strict-transport-security
max-age=31536000; includeSubDomains