chicoree.ch
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (2)
- www.google-analytics.com×2
- www.googletagmanager.com×2
Social
DNS records live
- NS
-
- ns-1041.awsdns-02.org
- ns-1845.awsdns-38.co.uk
- ns-266.awsdns-33.com
- ns-583.awsdns-08.net
- MX
-
- 0 chicoree-ch.mail.protection.outlook.com
- TXT
-
_c7hgpvzu71z9ue42roin5kd454o56u8_kmv7zki4fsypcu988fmkljftm8pe6o7
- Verified for
-
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 mx a ip4:212.98.34.0/25 include:_spf.google.com include:spf.protection.outlook.com include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyUEi07N3EbQzlDWFoCIdpVguMAlntDnYDHLHr6vaOPnnUrUuxhB4uqCQTEfGmr0cwgGX6y2wbYeF6T…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 71 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self';object-src 'none';connect-src 'self' https://api.chicoree.ch/v1/api/ https://d365apiprod.chicoree.ch *.getflowbox.com https://webservices.post.ch:17023/IN_SYNSYN_EXT/REST/v1/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.ch *.google.fr *.google.de sentry.io *.sentry.io https://consent.cookiebot.com https://consentcdn.cookiebot.com *.imgix.video https://tiktok.com https://www.tiktok.com/oembed https://webservices.post.ch:17023 https://s.pinimg.com/ https://ct.pinterest.com/;script-src 'self' blob: https://cdn.jsdelivr.net *.getflowbox.com https://www.tiktok.com/embed.js https://lf16-tiktok-web.ttwstatic.com https://www.youtube.com/ https://s.pinimg.com/ https://ct.pinterest.com/ https://tagmanager.google.com *.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://analytics.- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (7)
- youtube.com×1
- waurl.me×1
- tiktok.com×1
- spotify.com×1
- instagram.com×1
- facebook.com×1
- allink.ch×1