bookservices.eu
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- ajax.googleapis.com×2
- fonts.googleapis.com×2
- www.facebook.com×1
DNS records live
- NS
-
- ns-212-a.gandi.net
- ns-236-c.gandi.net
- ns-39-b.gandi.net
- MX
-
- 10 spool.mail.gandi.net
- 50 fb.mail.gandi.net
Email authentication partial
- SPF
-
v=spf1 include:_mailcust.gandi.net include:servers.etarget-emailing.com include:spf1.economist.com ?allneutral (?all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@edl.toolspolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src https: 'unsafe-inline' 'unsafe-eval';img-src 'self' secure.gravatar.com *.bookservices.eu www.facebook.com data:;font-src 'self' fonts.googleapis.com fonts.gstatic.com data:; object-src 'self' data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.bookservices.eu ajax.googleapis.com www.google.com www.gstatic.com connect.facebook.net js.stripe.com visites.edl.tools; worker-src 'self' blob: https://m.stripe.network;- strict-transport-security
max-age=31536000; preload