axa-im.ch
HTML metadata
Technology
- CDN
- Azure Front Door
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (4)
- cdn.cookielaw.org×1
- cdn.jsdelivr.net×1
- cdnjs.cloudflare.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- a1-179.akam.net
- a10-65.akam.net
- a2-64.akam.net
- a20-65.akam.net
- a5-67.akam.net
- a7-67.akam.net
- MX
-
- 10 mrelay2.axa.com
- TXT
-
Show 4 TXT records
vpq9jfvjww9bdfwwccmsc83txstf1v0s869g1cdvfzzngs6998cmk7tstbx0q3tv_v7w9qlqgiln6c90fguzbdsqduzdwf3bv63cgh727xsyp69wfzbst22w6sv63qmz
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; pct=100; rua=mailto:ewai10d2@ag.eu.dmarcian.com; ruf=mailto:ewai10d2@fr.eu.dmarcian.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Thawte TLS RSA CA G1
Expires in 185 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY, sameorigin- x-content-type-options
nosniff- content-security-policy
default-src *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com sc-static.net *.kaltura.com *.google-analytics.com *.edgekey.net *.cloudflare.com *.jsdelivr.net *.en25.com *.facebook.net *.licdn.com *.en25.com *.googletagmanager.com *.newrelic.com *.licdn.com *.bing.com *.brighttalk.com *.axa-im.ch *.cookielaw.org *.aticdn.net *.fullstory.com *.ceros.com *.ausha.co; object-src self; style-src 'self' 'unsafe-inline' *.googleapis.com *.cloudflare.com *.fontawesome.com; img-src https: data: https://www.axa-im.ch; media-src https: data: blob:; frame-src self *.youtube-nocookie.com *.doubleclick.net *.facebook.com *.googletagmanager.com *.brighttalk.com *.axa-im.ch *.ceros.com *.kaltura.com *.ausha.co; frame-ancestors self; child-src self blob:; font-src data: fonts.gstatic.com *.googleusercontent.com *.axa-im.com *.axa-im.co.uk *.kaltura.com *.axa-im.ch; connect-src *.axa-im.com *.axa-im.co.uk *.kaltura.com *.edgekey.net *.google-analytics.com *.google.com *.facebo