coromant.com
HTML metadata
Technology
- Server
- volt-adc
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×1
- khvj4m9xsa.kameleoon.eu×1
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 1996-09-23
- Expires
- 2026-09-22 125 days left
- Updated
- 2025-09-18
- Name servers
-
- ns.sandvik.com
- nx1.sandvik.com
- nx2.sandvik.com
- nx3.sandvik.com
DNS records live
- NS
-
- ns.sandvik.com
- nx1.sandvik.com
- nx2.sandvik.com
- nx3.sandvik.com
- MX
-
- 0
- TXT
-
Show 11 TXT records
MS=ms56675605ohgkn85telugkv73ekb5ff6302fah86nia65u2rpgkkfbbivshppkvbdg69uibeusfhqnbsc3ltb5hradfcipipe8mj4t7upj8irmiqiswisssign-check=e4t-PdWWQFun4lylQVTXfIbYiRsswisssign-check=SygbyzgZJJqQ49klb8lU9VEKlE1EL2TsI4MTdeCaKDheyhack-verification=ee606d4d-31c7-4661-ab2c-c330b250baa7nm73bq1mhqd8cr1znr6rxtfp8tyhxxb4agdgv80uf0blt1lpctkohhmdosswisssign-check=iVdI25fOKajTL4oXk8LrYup-X14
Email authentication strong
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;fo=1;ri=3600;rua=mailto:dmarcrua@sandvik.com;ruf=mailto:dmarcruf@sandvik.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
SwissSign RSA TLS OV ICA 2022 - 1
Expires in 98 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), gyroscope=(), magnetometer=(), microphone=(), usb=() on-device-speech-recognition=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; frame-src 'self' https://*.coromant.com https://*.coromant.cn https://d6tizftlrpuof.cloudfront.net https://oc-cdn-public-eur.azureedge.net https://*.marketo.com https://*.googletagmanager.com https://static.experimentation.dev https://*.google.com https://*.adyen.com https://videos.sandvik.coromant.com; style-src 'self' 'unsafe-inline' https://*.bing.com https://oc-cdn-public-eur.azureedge.net https://*.marketo.com https://*.googletagmanager.com https://*.googleapis.com https://static.experimentation.dev https://*.adyen.com https://*.mopinion.com; script-src 'self' blob: 'unsafe-eval' 'nonce-bHmYidnSaw6dP6jt_6Tg7cKcK0BullC1' https://*.analytics.google.com https://*.google-analytics.com https://*.g.doubleclick.net https://www.google.com https://www.recaptcha.net https://cdn.cookielaw.org https://*.onetrust.com https://hm.baidu.com https://*.googletagmanager.com https://*.kameleoon.eu https://*.marketo.net https://*.mopinion.com https://d6tizftlrpuof.cloudfront.net ht- strict-transport-security
max-age=31536000