welion.it
HTML metadata
Technology
- CMS
- Gatsby
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns3.interbusiness.it
- ns1.generali.it
- ns2.generali.it
- MX
-
- 4 generali-com.mail.protection.outlook.com
- Verified for
-
- GlobalSign
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:138.1.0.0/16 ip4:92.246.34.85 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc-rua@generali.com; sp=quarantine; adkim=r; aspf=r; fo=1; ri=86400policy: quarantine · sp=quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAruivn67tb9PoSGXh9ip5yDkcBydc2mJ9CupMb1KXH3EcykNk0wkjlLI4S8eTR2mYZ78OGDZDFItDPk… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3CthWrdl1EKTj37/+K1k/p19HHKryzWuizWpwOLGZ3QemhTyzxSIampKGH1bVYMFX1yC53fLYQ7efG…
selectors probed - selector1:
Certificate (current)
Sectigo RSA Organization Validation Secure Server CA
Expires in 226 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
Origin- x-frame-options
Deny- x-content-type-options
nosniff- content-security-policy
block-all-mixed-content; default-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.kaltura.com https://*.generali.com https://*.vivocha.com/ https://convy.unyco.net https://www.youtube.com/ https://www.google-analytics.com; script-src 'self' https://*.welion.it https://*.analytics.edgekey.net https://convy.unyco.net https://*.cookielaw.org https://*.vivocha.com/ *.google.com *.gstatic.com *.googleapis.com https://www.google-analytics.com *.kaltura.com https://www.googletagmanager.com https://tags.bluekai.com 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline' *.google.com *.googleapis.com *.gstatic.com; img-src 'self' https://developers.google.com *.analytics.google.com https://*.cookielaw.org https://facebook.com https://via.placeholder.com https://maps.googleapis.com data: *.gstatic.com *.googleapis.com *.google-analytics.com https://*.kaltura.com https://convy.unyco.net https://*.vivocha.com/; media-src 'self' blob: https://*.kaltura.com https://*.welion.it https://*.g- strict-transport-security
max-age=63072000; includeSubDomains
Links to (12)
- youtube.com×1
- venchi.com×1
- linkedin.com×1
- lilly.com×1
- irenlucegas.it×1
- h-farm.com×1
- generali.it×1
- generali.com×1
- europassistance.it×1
- dana.com×1
- cerved.com×1
- cefla.com×1