carbagas.ch
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Drupal
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (19)
- be.airliquide.com×2
- at.airliquide.com×1
- bg.airliquide.com×1
- de.airliquide.com×1
- dk.airliquide.com×1
- es.airliquide.com×1
- fi.airliquide.com×1
- fr.airliquide.com×1
- it.airliquide.com×1
- lu.airliquide.com×1
- nl.airliquide.com×1
- no.airliquide.com×1
- pl.airliquide.com×1
- pt.airliquide.com×1
- ro.airliquide.com×1
- se.airliquide.com×1
- tr.airliquide.com×1
- uk.airliquide.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns01.airliquide.com
- ns02.airliquide.com
- ns03.airliquide.com
- ns04.airliquide.com
- MX
-
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 2 aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
sending_domain1053103=6b2e88369762af6b67afcba3be8c87d977492ffada7c6638b6bf03eb30b1edf9pardot1053103=4929c29c7e2de4419646ece2c5e92762851bcf3b9174eb24022f063c28b8e187dlwp33qpynnf3y13zym2tc8564xh3wcqgbgrpwgbt67cw5vnq56n5l3f8cgkrhq1pardot773312=f6734c77abdd8139b95854962845f846fa54fea03aa929f694a26aa658fbcd07sending_domain547722=91c212db6e5610a067d6891417c361574053f2323ca3cb9efddc93de9618575e
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:185.188.176.0/22 ip4:90.80.28.0/28 include:_spf.google.com include:spf.mailjet.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc.rua@carbagas.chpolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzAfLrUv71SYaDmqtkv20xgwYh/7Wg00WEUSlIGR3eAk/IObAgU06i9I1NIJWvgEydeHgpel5G72h8+…
selectors probed - google:
Certificate (current)
Sectigo Public Server Authentication CA OV E36
Expires in 255 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com www.google-analytics.com optimize.google.com www.googleoptimize.com api-public.addthis.com https://api-public-oci-origin.addthis.com https://m.addthis.com https://q.addthis.com https://s7.addthis.com https://www.addthis.com https://v1.addthisedge.com graph.facebook.com https://z.moatads.com https://widgets.pinterest.com https://vk.com/share.php https://www.odnoklassniki.ru/dk https://connect.ok.ru/dk https://www.googleadservices.com snap.licdn.com *.hotjar.com googleads.g.doubleclick.net amplify.outbrain.com wave.outbrain.com tr.outbrain.com www.youtube.com pi.pardot.com pi.demo.pardot.com go.airliquide.com cdn.jsdelivr.net unpkg.com maps.googleapis.com *.signalfx.com *.piwik.pro *.direct.worldline-solutions.com *.optimonk.com *.googleoptimize.com *.intercom.io *.intercomcdn.com info.go.airliquide.com slsntllgnc.com *.lfeeder.com *.privacy-center.org *.visualwebsiteoptimizer.com app.vwo.com *.a- strict-transport-security
max-age=16070400; includeSubDomains