agrealestate.eu
HTML metadata
Technology
- Server
- .NET
- CMS
- WordPress
- jQuery
- 2.2.4 known XSS (<3.5)
- Cookie consent
-
- OneTrust
- Fonts
-
- Adobe Fonts
- Font Awesome
Third-party hosts loaded (10)
- cdn.jsdelivr.net×4
- cdnjs.cloudflare.com×4
- cdn.plyr.io×3
- code.jquery.com×2
- rawgit.com×2
- unpkg.com×2
- use.fontawesome.com×2
- use.typekit.net×2
- cdn.cookielaw.org×1
- www.google.com×1
Social
Contact
DNS records live
- NS
-
- ns1.register.be
- ns2.register.be
- ns3.register.be
- MX
-
- 10 mx07-00218201.pphosted.com
- 10 mx08-00218201.pphosted.com
- TXT
-
Show 8 TXT records
autodesk-domain-verification=735EW7YZIm2MA7j6SXQtspf2.0/pra include:spf.flexmail.eu ?allYAARBVTZHmZgs4azmwyKA2b9/lA4s7flXWkQQBvuOR8=4oxKYxRfVAvtX3+FvVsY8/cE+xPk1JP3/Myp0kPSJ6E=G97wVBeDRsgu5tsp6b6nd2vl11u5ye0MPu/fflKnX5o=Zr8JaKW67iz8aIJF9VibDQCzths1WmI2LgHmJ2Lkr54=/644X8HIY1I1fziNDd7MJC3RVFnEx8l+gLPIQTlRekk=GJZaale5FSmi8fe4IfI7P4gWGKc2x2TOMDk+thuS31w=
- Verified for
-
- Adobe
- Apple
- Brevo
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; fo=1policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCiy435+4Q4n5FeDlJzzVPDOy3mkpsNdG5owetycnxBU41EQP9UIm2K9QShAJe4y+9fPzZkmE1Nzq+/IPSO9m… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA65VO3QmEjYdYhRAvgQaidLG6xuzlN3YSmo+jl4C2Za6EESp00wYFFsKUtBiETl9+Cpu25xw7pQ9+S8… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - google:
Certificate (current)
R13
Expires in 70 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
sameorigin, SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *; style-src 'self' 'unsafe-inline' * data:; font-src 'self' data: *; img-src 'self' data: *; connect-src 'self' data: webpack: *; frame-src 'self' *;- strict-transport-security
max-age=31536000- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin
Links to (5)
- un.org×1
- twitter.com×1
- linkedin.com×1
- google.com×1
- agrealestate.fr×1