whysecurity.it
HTML metadata
Technology
- CDN
- Cloudflare
DNS records live
- NS
-
- elaine.ns.cloudflare.com
- zeus.ns.cloudflare.com
- MX
-
- 0 mx01.falconmail.tech
- 100 mx10.whysecurity.it
- TXT
-
canva-domain-verify=2e754c23-230d-458b-a55a-a5aaa211ab36
Email authentication strong
- SPF
-
v=spf1 include:spf0.whysecurity.it ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=quarantine;pct=100;rua=mailto:8f2e1b7dd1484c9aa55b5d3199d1356c@dmarc-reports.cloudflare.netpolicy: quarantine - DKIM
-
- default:
v=DKIM1;k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCi9JN+1Lfc+DLBo1JVeP0Sdj20vp98AO0iS19bv8PWTuCKCJr5wjy/ZebA/3NRARQ5ZrDz3km7fUrYhs9ByXqt… - selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDkosHeRTaGEey851bUb1sOZt7B1ljmMc2qFHMsjOeB6k9Svz0V6g9CItDRoW6Sst2YfVKBhtl02IrnNZMbQ…
selectors probed - default:
Certificate (current)
WE1
Expires in 68 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' *.canva.com canva.com; report-uri https://csp.canva.com/_cspreport?app=websites; base-uri 'self'; object-src 'none'; script-src 'report-sample' 'strict-dynamic' 'nonce-c384011b-8fe6-45f6-8029-d076056f4d81' 'wasm-unsafe-eval' https://www.google.com/recaptcha/api.js;- strict-transport-security
max-age=31536000
whysecurity.it