centrakor.com
HTML metadata
Technology
- CMS
- Gatsby
- Ads
-
- Meta Pixel
Third-party hosts loaded (3)
- connect.facebook.net×1
- www.tiktok.com×1
- xeq45mk265.kameleoon.io×1
Social
Registration
- Registrar
- Gandi SAS
- Created
- 1999-02-11
- Expires
- 2027-02-11 266 days left
- Updated
- 2026-01-11
- Name servers
-
- ns1.cargo-webproject.com
- ns2.cargo-webproject.com
DNS records live
- NS
-
- ns1.cargo-webproject.com
- ns2.cargo-webproject.com
- ns3.cargo-webproject.com
- MX
-
- 10 mx1.hc895-62.eu.iphmx.com
- 20 mx2.hc895-62.eu.iphmx.com
- TXT
-
4/mx7uscF/H3P+9gu15NN7Rzc48=
- Verified for
-
- Microsoft 365
- Zoom
Email authentication strong
- SPF
-
v=spf1 a mx include:mes-mails.net include:spf.mandrillapp.com include:spf.protection.outlook.com include:cartsguru.io ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=10; rua=mailto:dmarc@cargo-services.fr; ruf=mailto:dmarc@cargo-services.fr; fo=1;policy: quarantine · pct=10 - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3UhGtRALjkIPvcho28sY+c61j1Ne3AKf5RVq22KDOMm0JCfbR7wjo0TRvCQveB9mglK6vHoCwM3+70…
selectors probed - selector1:
Certificate (current)
R13
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' maps.googleapis.com *.hipay.com static.cdn.prismic.io prismic.io https://html2canvas.hertzen.com/dist/html2canvas.min.js www.paypalobjects.com *.paypal.com youtube.com vimeo.com https://www.youtube.com/iframe_api https://www.youtube.com/s/player/0c356943/www-widgetapi.vflset/www-widgetapi.js https://www.youtube.com https://i.ytimg.com/vi/ http://platform.instagram.com/en_US/embeds.js https://www.instagram.com/embed.js https://graph.facebook.com/v11.0/instagram_oembed https://player.vimeo.com/api/player.js https://player.vimeo.com/ js.stripe.com *.googletagmanager.com googletagmanager.com https://www.google-analytics.com http://www.google-analytics.com https://gtm.zone-secure.net https://yt.zone-secure.net http://www.gstatic.com https://*.attraqt.io https://*.facebook.net/ https://*.teads.tv/ https://*.smartlook.com/ https://*.hotjar.com/ https://*.doubleclick.net https://*.mathtag.com https://*.tiktok.com/ https://*.ttw- strict-transport-security
max-age=31536000; includeSubDomains