almaval.ch

.ch crawl

First seen 2026-05-30 · Last seen 2026-05-31 · ok HTTP/1.1 200 302 ms crawled 2026-05-31

FR · 185.30.92.231 · AS60491 B2 Network SARL

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Almaval
Language
fr-FR
Generator
WordPress 6.7.1
Canonical
https://almaval.ch/
Translations
  • en
  • fr
Feeds

Technology

Server
nginx
CMS
WordPress 6.7.1
jQuery
3.7.1
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • fonts.googleapis.com×4
  • fonts.gstatic.com×1
  • www.google.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

DNS records live

NS
  • paloma.ns.cloudflare.com
  • rocco.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • A7C025E5FA
Verified for
  • Google

Email authentication partial

SPF
v=spf1 a:my.almaval.ch include:_spf.google.com include:_spf.kreativmedia.ch ~all
softfail (~all)
DMARC
v=DMARC1; p=none; pct=100; rua=mailto:dmarcreports@lovable.dev
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArpQhb7z4ewGp4tfWCmC7MLaKdpxf/iwC1DRB5yIs5cQhNbkSrnXclgP+J7t860NoV0kSNelKMvqNMJ…
selectors probed

Certificate (current)

R13
from 2026-04-25 to 2026-07-24
Expires in 53 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://almaval.ch/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval'; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://msr.sunethic.fr https://invitejs.trustpilot.com https://sibautomation.com https://conversations-widget.sendinblue.com https://www.google.com/recaptcha/ https://api.goaffpro.com/ https://conversations-widget.brevo.com/ https://widget.trustpilot.com/ https://cdn.sunethic.fr/ https://www.youtube.com/ https://ajax.googleapis.com https://www.googletagmanager.com https://checkout.postfinance.ch https://app-wallee.com https://*.paypal.com https://*.paypalobjects.com https://cdn.pushowl.com https://consent.cookiebot.com https://assets.calendly.com https://cdn.brevo.com/ https://pagead2.googlesyndication.com/ https://tally.so https://sibforms.com https://*.cloudfront.net unsafe-eval https://cdn.by.wonderpush.com https://chimpstatic.com https://js.stripe.com https://nlpd.alfavin.ch https://assets.prestashop3.com https://*.b-cdn.net https://cdn.jsdelivr.net https://embed.tawk.to https:/

Links to (44)

Linked from (1)