cointreau.com
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Analytics
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (5)
- www.googletagmanager.com×2
- assets.pinterest.com×1
- cdn.cookielaw.org×1
- try.abtasty.com×1
- www.google-analytics.com×1
Social
Registration
- Registrar
- Nameshield SAS
- Created
- 1995-10-11
- Expires
- 2026-10-10 143 days left
- Updated
- 2025-10-08
- Name servers
-
- ns2.observatoiredesmarques.fr
- ns3.nameshield.net
- obs.ns1.fr
DNS records live
- NS
-
- ns2.observatoiredesmarques.fr
- ns3.nameshield.net
- obs.ns1.fr
- MX
-
- 0 eu-smtp-inbound-psc-1.mimecast.com
- 0 eu-smtp-inbound-psc-2.mimecast.com
- TXT
-
Show 6 TXT records
0ed1fe018a88e6b947293b47738a22e056fbe7c923shopify-verification-code=GhbTVr0gUCIC8p6C8qlmMqkJjhGIxC7s48jd8hwfkjlrsxxhpnswlkn66x37z3h2610rhrpxqqc5jhgcjc2ftsmwgnztwnMS=ms85210376google-site-verification=UCzjGPNpbYqxLISr3JYEHZFV_4GY8DUbtInSh5T3NBY
Email authentication strong
- SPF
-
v=spf1 include:_spf.salesforce.com include:eu._netblocks.mimecast.com -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;fo=1;rua=mailto:jt6k13au@ag.eu.dmarcian.com; ruf=mailto:jt6k13au@fr.eu.dmarcian.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Encryption Everywhere DV TLS CA - G2
Expires in 125 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-hashes' 'unsafe-inline' 'unsafe-eval' data: blob:; connect-src *; font-src 'self' *.swaven.com *.static-swaven.com https://static.tacdn.com/css2/webfonts/TripAdvisor/ https://fonts.gstatic.com https://cdn.ventrata.com; frame-src *; img-src * data: blob:; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; script-src-elem * 'unsafe-inline' data: blob:; style-src * 'unsafe-inline' data: blob:; frame-ancestors *- strict-transport-security
max-age=63072000; includeSubdomains; preload