acuvue.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (3)
- images.contentstack.io×7
- brand.jjvision.com×4
- static.cloudflareinsights.com×1
Registration
- Registrar
- Key-Systems GmbH
- Created
- 1997-06-20
- Expires
- 2027-06-19 383 days left
- Updated
- 2026-05-18
- Name servers
-
- dns1.p01.nsone.net
- dns2.p01.nsone.net
- dns3.p01.nsone.net
- dns4.p01.nsone.net
- ns01.jnjdns.com
- ns02.jnjdns.com
- ns03.jnjdns.com
- ns04.jnjdns.com
DNS records live
- NS
-
- dns1.p01.nsone.net
- dns2.p01.nsone.net
- dns3.p01.nsone.net
- dns4.p01.nsone.net
- ns01.jnjdns.com
- ns02.jnjdns.com
- ns03.jnjdns.com
- ns04.jnjdns.com
- MX
-
- 5 mx1.jnj-sd.iphmx.com
- 5 mx2.jnj-sd.iphmx.com
- CNAME
-
- acuvue.com.cdn.cloudflare.net
- Verified for
-
- Brevo
Email authentication no MX
- SPF
- not published
- DMARC
-
v=DMARC1; p=reject; pct=100; sp=reject; rua=mailto:5d14eac2@inbox.ondmarc.com; ruf=mailto:5d14eac2@inbox.ondmarc.com; adkim=r; aspf=r; fo=1; rf=afrf; ri=3600policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src *; font-src * data: blob:; media-src * data:; frame-src 'self' mailto: tel: *.acuvue.com *.acuvue.ru *.adsrvr.org *.brightcove.com *.brightcove.net *.cloudflare.com *.doubleclick.net *.eprize.net *.google.com *.googletagmanager.com *.livechatinc.com *.mypurecloud.com *.opinionstage.com *.optimizely.com *.platformsh.site *.qualtrics.com *.surveymonkey.com *.valassis.eu *.voiston.ai *.walkme.com *.walls.io *.yandex.ru *.yandex.com *.contentstack.io *.youtube.com; frame-ancestors 'self' *.ta-to.com; img-src * data: blob:; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.adsrvr.org *.ads-twitter.com *.amazon-adsystem.com *.appsflyer.com *.clarity.ms *.cloudflare.com *.cloudflareinsights.com *.contentsquare.com *.contentsquare.net *.contextweb.com *.cookielaw.org *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.jquery.- strict-transport-security
max-age=31536000; includeSubDomains