belbin.es
HTML metadata
Technology
- CDN
- Cloudflare
Third-party hosts loaded (3)
- cdn.popt.in×1
- www.belbin.com×1
- www.google.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- sloan.ns.cloudflare.com
- uriah.ns.cloudflare.com
- MX
-
- 10 belbin-es.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
google-site-verification=fAAjEFfvWNj8p2JTnqx8U8VI-DtBVfcwz4nT0EXIkkcv=spf1 ip4:77.104.135.182 include:spf.protection.outlook.com include:eu.zcsend.net include:transmail.net include:eu-sender.zohobooks.com -allMS=ms26546099google-site-verification=-diaa-exGQWIdWAAatrZoVUIL4MKlI-xinJGjfQw4p0
Certificate (current)
WE1
Expires in 19 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SameOrigin- x-content-type-options
nosniff- content-security-policy
script-src *.agilecrm.com *.cdn-cookieyes.com *.cloudfront.net *.cookieyes.com *.facebook.net *.google.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.licdn.com *.onetrust.com *.responseiq.com *.whoisvisiting.com *.youtube.com cdn2l.ink cdn-cookieyes.com 'self' 'unsafe-eval' 'unsafe-inline';script-src-elem *.agilecrm.com *.amazonaws.com *.cdn-cookieyes.com *.clarity.ms *.cloudfront.net *.cookieyes.com *.facebook.net *.google.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.licdn.com *.list-manage.com *.onetrust.com *.popt.in *.responseiq.com *.trustpilot.com *.whoisvisiting.com *.youtube.com cdn2l.ink cdn-cookieyes.com cdnjs.cloudflare.com reviewsonmywebsite.com 'self' 'unsafe-inline';font-src *.amazonaws.com *.cdn-cookieyes.com *.cloudfront.net *.googleapis.com *.gstatic.com *.popt.in cdnjs.cloudflare.com data: 'self' 'unsafe-inline';connect-src *.ap3prod.com *.belbin.com *.cdn-cookieyes.com *.clarity.ms *.cloudfront.net *.c- strict-transport-security
max-age=31536000; includeSubDomains; preload