ca-indosuez.com
HTML metadata
Technology
Third-party hosts loaded (2)
- leaflet.github.io×3
- unpkg.com×2
Social
Contact
- Phone
Registration
- Registrar
- Nameshield SAS
- Created
- 1997-06-04
- Expires
- 2026-06-03 14 days left
- Updated
- 2025-06-02
- Name servers
-
- chenar.credit-agricole.fr
- ramses.credit-agricole.fr
DNS records live
- NS
-
- chenar.credit-agricole.fr
- ramses.credit-agricole.fr
- MX
-
- 10 mercure.credit-agricole.fr
- TXT
-
Show 8 TXT records
apple-domain-verification=704uRMT5F71sPWoibrevo-code:bc539b2857630284d48c949ddba2d242MS=29CDAD2A4BA1C8C5CE673A139F9F780CDD2B64F8adobe-idp-site-verification=d50cf1548aa410306a1c7e0c9c7b2634ab6dca16873615ebedea82605af715ec8SVRFD5A389MJ5QBSFGRHTP5TFcisco-ci-domain-verification=3aeb0436cd9c6dbf47881ace4bdb202dbb6cf9bb77b50ee4b4709103d5c8054bMS=ms65437808google-site-verification=7jcAbxPHnJOFgpDpWk8KJ5qf546bUF-wMQYSXbGQVFk
Email authentication strong
- SPF
-
v=spf1 a:spf.credit-agricole.fr/24 include:spf.sendinblue.com include:spf.brevo.com mx/24 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; rua=mailto:rua@dmarc.ca-gip.fr; ruf=mailto:rsi@ca-indosuez.com; fo=1policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 260 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer, strict-origin-when-cross-origin- x-frame-options
DENY, SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'none'; connect-src 'self' noembed.com cdn.plyr.io www.google.com; font-src 'self' data:; form-action 'self' annuaire.group.gca; frame-ancestors 'self'; frame-src 'self' www.youtube.com www.google.com; img-src 'self' xiti.com *.xiti.com server.arcgisonline.com i.ytimg.com data:; media-src 'self' blob:; script-src 'self' 'unsafe-inline' www.youtube.com tag.aticdn.net xiti.com www.google.com www.gstatic.com leaflet.github.io unpkg.com/leaflet@1.6.0/dist/leaflet.js; style-src 'self' 'unsafe-inline' leaflet.github.io unpkg.com/leaflet@1.6.0/dist/leaflet.css- strict-transport-security
max-age=600; includeSubDomains