carglass.fi
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- openresty
- JS framework
- Angular 18.2.14
Social
Contact
- Phone
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 0 carglass-fi.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
- Workplace
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:69.72.37.240 ip4:212.50.156.102 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; rua=mailto:it@carglass.dk;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzs9Hya15NioT6pSPb8dQIRRWvUtffFQSZFzA/3zQjpZHh3sIASVpiH3V5nl7t2J2eJW0IwzqYmLvoI… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAppW3ppxOFubLEkUKB4uwS/aQidF4WMRFBUqjWgEPKZbfFa6dTG5HwdjIsRc0wq53lOFah9m2uIpYMbBgiH… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDhth3t5bwd9TPSP91gluzNMNxsVvhJQ/PfcWerLs7k/1bdxPLvVLLnmn/1AlVi/j4akWw/gWAxvPGjlT6QkmSI1V…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 255 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self "https://*.ewp.belron.com" "https://api.woosmap.com"),midi=(),sync-xhr=(self "https://*.ewp.belron.com" "https://rum.browser-intake-datadoghq.eu"),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"),payment=()- x-content-type-options
nosniff- content-security-policy
connect-src 'self' *.ewp.belron.com https://*.puzzel.com https://tracking.carglass.fi https://tracking.carglass.dk https://tracking.carglass.se https://tracking.carglass.fi https://tracking.carglass.no https://olb-assets-ewp-euc1-prd.s3.eu-central-1.amazonaws.com https://cta-service-cms2.hubspot.com https://forms.hubspot.com https://api.hubapi.com https://collect-eu-central-1.tealiumiq.com https://logx.optimizely.com https://ampcid.google.com https://www.facebook.com https://staticw2.yotpo.com https://w2.yotpo.com https://cdn.cookielaw.org https://conductor.clicktale.net https://www.google-analytics.com http://*.hotjar.com:* https://*.hotjar.com:* https://vc.hotjar.io:* wss://*.hotjar.com https://tapi.optimizely.com https://s7.addthis.com https://bat.bing.com https://m.addthis.com https://europe-west1-carglass-dk-dlp.cloudfunctions.net https://stats.g.doubleclick.net https://privacyportal-eu.onetrust.com https://api.yotpo.com https://api-iam.intercom.io wss://nexus-websocket-a.intercom- strict-transport-security
max-age=31536000; preload