chipotle.co.uk
HTML metadata
Technology
Third-party hosts loaded (3)
- a40.usablenet.com×1
- services.chipotle.com×1
- vice-prod.sdiapi.com×1
Social
DNS records live
- NS
-
- ns-1229.awsdns-25.org
- ns-2043.awsdns-63.co.uk
- ns-314.awsdns-39.com
- ns-564.awsdns-06.net
- MX
-
- 10 mxa-00200801.gslb.pphosted.com
- 10 mxb-00200801.gslb.pphosted.com
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.emailpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 101 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' sdiapi.com app.datadoghq.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub6df94c90ac4e89b7d31cb3f4ac5cc298&dd-evp-origin=content-security-policy&ddsource=csp-report; script-src 'self' blob: 'nonce-ahwxol7ctyr4q2HI63j5kQAAAE4' 'strict-dynamic' 'unsafe-inline' https: http: ;object-src 'none';base-uri 'self';- strict-transport-security
max-age=31557600