cordongroup.com
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- ajax.googleapis.com×1
Social
Registration
- Registrar
- Gandi SAS
- Created
- 2010-11-26
- Expires
- 2026-11-26 190 days left
- Updated
- 2026-03-18
- Name servers
-
- karl.ns.cloudflare.com
- wally.ns.cloudflare.com
DNS records live
- NS
-
- karl.ns.cloudflare.com
- wally.ns.cloudflare.com
- MX
-
- 0 fortimail.cordongroup.com
- 10 cordongroup-com.mail.protection.outlook.com
- TXT
-
Show 20 TXT records
docusign=12496f29-e10f-48b4-8c5e-fc720470220cglobalsign-domain-verification=eef7cb54a0e1afc893759aaa7d126312google-site-verification=t9240t556mtNs9JLjbYv13jZOnkvCgMq_wdVDoYTrhkatlassian-domain-verification=IDiL7jMzg1na3JaCGx8GxpFpudBabLdE1kcpGqtaDJB29LDQffhyPXNtxygIia4Tdocusign=926e4576-657f-4e20-8068-d6e716170b54globalsign-domain-verification=70d0e9e76edfc7bfa126dd415abf4a935ng3YQBuHb2LWXaJGNLCBRapple-domain-verification=EWE9eMrtAkCoQcpfsamsung-domain-verification=5c6044c2-11fe-46f6-be83-40de3d0bd14d3JRw33q+yhrxAofL6IS8fG1czuuZlfYeWexPxBFU78A=have-i-been-pwned-verification=e90ee642c5700593f2d50ecb8eb0a2bbAV3L1nRVED7AyVy6Jvd/nAudRkS281BPaSh4J68ERFhixxaLLXVW+FD2rhepcYzPIqM06N5cAi/mAkEPAldzKw==anthropic-domain-verification-grhwjq=zDLLHkfBIXeSRr1jG4WIF5YoConeuptime-verification-ohPcZMzRwsWKTxMFBxZVgoogle-site-verification=74hwfl9P1tbum8nwtL8Ls8trdmxamSIqY9sVEtLztZEcisco-ci-domain-verification=70dbdbe0b816d0299147489cf0b264d913353162792f52e2369c3a197e5e21b3TXT token : docusign=926e4576-657f-4e20-8068-d6e716170b54_globalsign-domain-verification=hHTPl0m-0aZbYRL1DHO9bnXnLIY9-UeDuDq5DhXkb5MS=ms56907169bw=whKX5mto04sQRM2/rsyNmnPOlK+9k720k/f7evRSpJ1E
Email authentication strong
- SPF
-
v=spf1 mx include:spf.cordongroup.com include:spf.mailjet.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=10; rua=mailto:dmarc-rua@cordongroup.com; ruf=mailto:dmarc-ruf@cordongroup.compolicy: quarantine · pct=10 - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyiKhxx1R1ZRtpZM7bPa7XvparQjvqq8KOHec29WZcPC/gsjsC2hLNRu9CcIr2RYP9qfdvivuAnn5y/… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwusoT6Js/vFz2fweUs1FJ8AJ7SweIPeWIdPEEjGxBvNh59ho2ogWSdyxfrh5FbCNLg9l4K0AMTp7Gk…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
Header values
- referrer-policy
same-origin, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
interest-cohort=()- x-content-type-options
nosniff, nosniff- content-security-policy
frame-ancestors 'self', default-src 'self' *.axept.io www.google.com *.clarity.ms; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: ajax.googleapis.com www.googletagmanager.com www.google.com *.axept.io *.clarity.ms www.gstatic.com www.google-analytics.com; img-src 'self' data: ps.w.org *.gravatar.com favicons.axept.io axeptio.imgix.net *.clarity.ms *.bing.com; media-src 'self' *.vimeo.com *.vimeocdn.com vod-progressive.akamaized.net data:; connect-src 'self' *.clarity.ms *.axept.io *.google-analytics.com cordongroup.piwik.pro; frame-src 'self' www.google.com www.youtube.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; font-src 'self' fonts.gstatic.com data:; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' cordongroup.piwik.pro ajax.googleapis.com www.googletagmanager.com www.google.com www.gstatic.com *.axept.io *.clarity.ms;- strict-transport-security
max-age=31536000; preload