amway.be
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- Next.js
- JS framework
- Next.js
Third-party hosts loaded (3)
- images.contentstack.io×8
- static.ada.support×1
- tags.tiqcdn.com×1
DNS records live
- NS
-
- dns1.p05.nsone.net
- dns2.p05.nsone.net
- dns3.p05.nsone.net
- dns4.p05.nsone.net
- MX
-
- 10 mxa-00026401.gslb.pphosted.com
- 20 mxb-00026401.gslb.pphosted.com
- TXT
-
U3RuY8dQ2bvnLcwTMvuZ9_1lnYF5_wuC6rkFKJ4PZe8
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 214 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src * data: 'unsafe-inline' 'unsafe-eval' 'self' blob:; media-src * blob:; img-src * data: 'unsafe-inline' blob: *.visualwebsiteoptimizer.com cdn.pushcrew.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com *.heapanalytics.com https://*.qualtrics.com; font-src * data: 'unsafe-inline'; frame-ancestors *.amway.it; connect-src 'self' api-js.datadome.co *.amway.eu https://siteintercept.qualtrics.com https://maps.googleapis.com *.visualwebsiteoptimizer.com app.vwo.com https://*.clarity.ms https://c.bing.com *.auryc.com https://amway-api.exponea.com https://*.ada.support https://*.qualtrics.com https://edge.api.brightcove.com http://manifest.prod.boltdns.net https://*.brightcovecdn.com; frame-src *.captcha-delivery.com https://*.elf.site https://players.brightcove.net geo.captcha-delivery.com https://coreplus.amwayglobal.com https://coreplus-qa.amwayglobal.com https://coreplus-regional.gmb-preprod.corp.amway.net https://coreplus-stage.amwayglobal.com *.qualtrics.com