aldi.es
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- Apache
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (4)
- cdn-fe-service.prod.an-cms.com×5
- app.usercentrics.eu×1
- assets.adobedtm.com×1
- cdns.gigya.com×1
Social
DNS records live
- NS
-
- ns-1087.awsdns-07.org
- ns-133.awsdns-16.com
- ns-1565.awsdns-03.co.uk
- ns-900.awsdns-48.net
- MX
-
- 10 aldi-es.mail.protection.outlook.com
- TXT
-
hPAi9VyEAWAVsb79YUcbPgqS4Ki/hpZwQ4UUhkz4KDiz36TfulXpM3ppVcHz6d+XyGO6RPFA5ojbjw6b63tmWw==miro-verification=86bb8a16f203a015e16e07df2d4e9edea0a88036swisssign-check=F-GGOFK5XW8Fa_sDOtDTAZGFxcU
Email authentication strong
- SPF
-
v=spf1 ip4:167.89.75.22 ip4:20.40.137.116/30 ip4:20.40.137.120/29 ip4:20.61.145.119 ip4:20.224.168.48 ip4:46.183.45.192/27 ip4:185.118.56.203 ip4:185.149.52.31 ip4:185.149.52.57 ip4:185.149.52.58 ip4:185.149.52.66 ip4:185.149.52.70 include:amazonses.com include:recruitmail.com include:spf.protection.outlook.com include:essprod0.templafy-ess.com include:spf.servicemail24.de include:_spf.salesforce.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:dmarc-rua@aldi-nord.de; pct=100; ri=86400policy: quarantine · sp=quarantine - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA07N/tegmPG4Yr1KyqlleiU7rmw6kg7XdfeQQ+dLkXdmjIePnKux1AZL1FkY49WWA1rxUkWx1XqUQTB… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0a95t7t0W5BI0rTbXyBN8zoDQwr+lElRaSftkO3Ae3S98Dhj9YOSSjacsQuqUzNYgWtcZ2HDf1mEwQ… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6848BptQYK7nWODFZNq7h50LxMX3fGpSHzHS0lBaZGBS89rXH89BB2C3EIzBPOTLjGVP6ZGylY727JoCAr… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDElXy+S21iMvjNULpuYBZd5q6RmjUR1hU9mfz+5W0xqxkZYZDS8PmSJ8ube8b2xw5evoHA99ZdOey7A4bFQUxke4…
selectors probed - selector1:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 249 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' folleto.aldi.es www.con-aldi.es experience.adobe.com aldinord.experiencecloud.adobe.com; default-src * 'unsafe-eval' 'unsafe-inline' data: blob:- strict-transport-security
max-age=31536000
Links to (10)
- google.com×4
- aldi.com×4
- facebook.com×4
- pinterest.es×4
- instagram.com×4
- youtube.com×4
- twitter.com×4
- linkedin.com×4
- tiktok.com×4
- apple.com×4