aldi-suisse.ch
HTML metadata
Technology
- CMS
- Nuxt
- Cookie consent
-
- OneTrust
Third-party hosts loaded (6)
- dm.emea.cms.aldi.cx×56
- assets.adobedtm.com×2
- cdn.cookielaw.org×2
- aldisued.tt.omtrdc.net×1
- publish.prod.emea.cms.aldi.cx×1
- www.aldi-sued.de×1
DNS records live
- NS
-
- udns1.cscdns.net
- udns2.cscdns.uk
- MX
-
- 1 asgportal.in.tmes.trendmicro.eu
- TXT
-
Show 18 TXT records
adobe-idp-site-verification=4813f4ab63fde94558b0581883685f00492480d445aacf979f4916eb28be60f1miro-verification=38ca58e3f143e17421169d4c41241f68462dddd4google-site-verification=P0n9r1k1DYy1kmc1HmZkZ4whWnfAQeaR97SdemNkT1capple-domain-verification=WX4DZjWvbcwAKlo4atlassian-domain-verification=cSRTDhs5UwDH4pea7XptFsuAk/N7XohIYFXb6raTgBq2N7luzhkuFEgm3qAbL0S7Dynatrace-site-verification=5b25eb9c-0e81-494d-8c6d-692c90e325c2__jrd5333v0epnp5g7feo0s4qh97FB5r04HrqwlFt3OQzh7Br9iy1ELiVLuCxG1D3RTFtm4lhkO+f5CFeHSdKydv4+hYsPKOa10Ui4kIDXnv6S91/g==pbMfzhC+9HD3UJfSu4VvpHn4tUFr47mm6h4doOPfIkX4a+BrFWNoxOqBs4pNkx8X+vV7BXZ+fZNl33pEnfigVw==tmes=ceed98e2be9f84706acac3bb195ab2d3mentimeter-7de74d17-8dc1-43fb-bc55-6d51cfef6e11knowbe4-site-verification=9aaca5fa2bbaeb5acc2b965cacd4a4b9MS=ms583046713ac1b9fc97604e45a204658c20a3a2d6facebook-domain-verification=qm10swsbbnd81w17q687mscxobdxhrbw=ZYciwgkKuzYwbCZ3RTrbNwSw5dUnTCgJDXI6TkLiNrVZdocusign=7c58da55-fee4-4df7-ab48-8eb4790cb733docusign=8cba6e45-9400-44f7-bf6f-f37aee0e8373knowbe4-site-verification=ff9339437acba116e403abeb2fdc35af
Email authentication strong
- SPF
-
v=spf1 redirect=aldi-suisse.ch.hosted.spf-report.comno all qualifier - DMARC
-
v=DMARC1; p=reject; rua=mailto:8a36a649@mxtoolbox.dmarc-report.com; ruf=mailto:8a36a649@forensics.dmarc-report.com; adkim=r; aspf=r; fo=1:d:spolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmIO+ykk4FwABd3Rma+ymDsVtyXqci6hZbU4luWABjaYIWTvtfPXgC99yHN0xr6nKSV4BVuiIVJEIUFBuq64… - mail:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC2IQGbWCjbbCpcJyJJSmiJrSdiCPCnfQYjhsEDgaFvOWrDK2CHekW8A3LpX9Xlrj7oJKYdpD3MHMFBDJ0A6R…
selectors probed - selector1:
Certificate (current)
E8
Expires in 32 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
bluetooth=(), camera=(), display-capture=(), hid=(), idle-detection=(), keyboard-map=(), local-fonts=(), microphone=(), midi=(), screen-wake-lock=(), serial=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), accelerometer=(self "https://www.youtube.com"), autoplay=(self "https://www.youtube.com"), clipboard-write=(self "https://www.youtube.com"), encrypted-media=(self "https://www.youtube.com"), fullscreen=(self "https://www.youtube.com"), geolocation=(self), gyroscope=(self "https://www.youtube.com"), picture-in-picture=(self "https://www.youtube.com"), web-share=(self "https://www.youtube.com"), payment=()- x-content-type-options
nosniff- content-security-policy
script-src https://*.cookielaw.org https://*.onetrust.com 'unsafe-inline' https://fe.ch.prod.commerce.ci-aldi.com https://fe.ch.prod.commerce.ci-aldi.com/payment-initiation-overview https://applepay.cdn-apple.com https://tags.tiqcdn.com https://*.tealiumiq.com https://assets.adobedtm.com https://*.demdex.net https://cm.everesttech.net https://*.dynatrace.com 'self' https://*.googletagmanager.com https://*.googleadservices.com https://*.googlesyndication.com https://*.google.com https://*.doubleclick.net https://*.doubleclick.com https://cdn.brcdn.com https://www.youtube.com https://locator.uberall.com https://*.mapbox.com https://*.2o7.net https://*.omtrdc.net https://*.adobe.com https://*.google.de https://*.google.at https://*.google.ch https://*.google.hu https://*.google.si https://*.google.it https://connect.facebook.net https://*.tiktok.com https://*.tiktokcdn.com https://p.teads.tv https://data.aldi-suisse.ch; connect-src https://*.cookielaw.org https://*.onetrust.com 'self' htt- strict-transport-security
max-age=15768000 ; includeSubDomains ; preload