autobernard.com
HTML metadata
Technology
Third-party hosts loaded (1)
- try.abtasty.com×1
Social
Registration
- Registrar
- Gandi SAS
- Created
- 1998-11-03
- Expires
- 2026-11-02 165 days left
- Updated
- 2025-09-26
- Name servers
-
- ns-101-b.gandi.net
- ns-34-c.gandi.net
- ns-61-a.gandi.net
DNS records live
- NS
-
- ns-101-b.gandi.net
- ns-34-c.gandi.net
- ns-61-a.gandi.net
- MX
-
- 0 autobernard-com.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
202008041326446apng7vp2r8qpwkkqz9pblsrsex5ixezoh6reuu6pfmnvd0b0kRJFH54HJIRWOamazonses:XHAL+ckT+oNuHiVoeBP6CCHhR0laNd3K9T7d+HUMdf8=NvzS/w5YasbYXSZw8yT9gScxXxMmFIrtk6vKLBItFZzQJKJZjYm1scXRIE32o33Na79Inv9ztpb4M7bZlG/78g==MS=AE1DFD1462831AAF8F2FF20AB9D313E96A65A079SFMC-LGC4aYyym0fmQ3OXxMNXtTJ3u66256mV-ZUzpxAF2021081207372045p681ipbgmfmf2hlnzgdvubkyijkqnbj3le7j7b7snv11j5ga
- Verified for
-
- Apple
- Brevo
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:87.98.180.180 ip4:89.31.148.98 ip4:195.154.172.72 ip4:37.58.247.158 ip4:15.237.239.36 include:spf.tmes.trendmicro.eu include:spf.protection.outlook.com include:spf.eu.exclaimer.net include:spf.mailjet.com include:143341066.spf01.hubspotemail.net include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com,mailto:dsi.admin@autobernard.compolicy: none (monitoring only) - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGmcVrPLjUQTdInydr2duv+jPee4sxjo+l3as6eW1BSHIJ8rnkkkGNk6Q+9byflrWgtWJUDcbsdjIFOY3uKS… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCos6h2P0dG+PpbgHMnAn1m3KhwULsxj922Q6+HrcCxR/ZL/T5vqUmK6Ea/Hepd0BWA4KGYZ6OWJJIQegKdk3… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAug+FpsecK1JiH2y0wQK8HW/CH7DudZNRjFSsdEk+zRx+DKN8a3449TQHcVPbfxM1WTOjNVKEWWIAoiY+nA… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDRyv20bHpaf+dYFk3uMDX6y3F4w/Hdwj14G0qdW9ZvqrEN9dSYZ/xbHSS3PUTD1SfrJiEakZAJEDrFi244A6UweL…
selectors probed - selector1:
Certificate (current)
GandiCert
Expires in 161 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(self), geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=(), speaker-selection=()- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'self' data:;script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.googleapis.com *.google.com *.googletagmanager.com googletagmanager.com *.googleadservices.com *.google-analytics.com *.credit-cgi.fr ui.vivafi.fr simulateur.vivafi.fr vivafi.fr *.facebook.net js.stripe.com *.crisp.chat *.abtasty.com *.ekonsilio.io *.hotjar.com *.hotjar.io openfpcdn.io *.axept.io *.doubleclick.net *.stampyt.io *.aticdn.net *.gstatic.com *.clarity.ms *.diago.ai *.youtube.com *.youtube-nocookie.com cdn.jsdelivr.net/npm/browser-image-compression@2.0.2/dist/browser-image-compression.js https://ca-auto-financing-widget-prod.ca-autobank.com/widget.js js.stripe.com m.stripe.com;frame-src 'self' *.google.com *.googleapis.com *.credit-cgi.fr ui.vivafi.fr simulateur.vivafi.fr vivafi.fr js.stripe.com *.youtube.com *.youtube-nocookie.com *.abtasty.com *.hotjar.com *.hotjar.io *.doubleclick.net *.googletagmanager.com *.diago.ai *.facebook.com https://data.autobernard.com js.stri- strict-transport-security
max-age=31536000; includeSubDomains