cote.co.uk
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- pat.ns.cloudflare.com
- terry.ns.cloudflare.com
- MX
-
- 10 cote-co-uk.mail.protection.outlook.com
- TXT
-
access-domain-verification=92c244baeefa7abf5aecf70b47ca00c3d31ea1bed5dce5e95074b9464d47dc218qqrs6afvkrvsabccpp13l64n3
- Verified for
-
- Apple
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.UK.exclaimer.net include:sendgrid.netfdspfus.freshemail.io -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:odkwp5vh4i@rua.powerdmarc.com,mailto:dmarc@cote.co.uk; ruf=mailto:odkwp5vh4i@ruf.powerdmarc.com; aspf=s;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvM5UCLcDPYg9VQNGnH1cOTGAzw3+v5P+/kt15xYLw2lWykgmzIPmPMmKRkmqbb6I6uDDP2LAwyDCAJ… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp2y3vJ2vEoKI9/P93CLKrhXwkcm6CxCJEGcaZb7hUXNBtB/nFmtfoOL0KYZ3emedHSdZjtok2Gyu1N…
selectors probed - selector1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; font-src 'self' data: https://*.userway.org https://*.exponea.com https://*.googleapis.com; media-src 'self' https://cote-renaissance-be-develop.azurewebsites.net https://cote-renaissance-be.azurewebsites.net https://*.exponea.com https://*.google.com https://*.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.stripe.com https://*.googletagmanager.com https://*.google-analytics.com https://*.clarity.ms https://*.bing.com https://*.google.com https://*.userway.org https://*.freshchat.com https://*.exponea.com https://*.yextapis.com https://*.tenkites.com https://*.applicationinsights.azure.com https://*.monitor.azure.com https://*.cookiebot.com https://*.facebook.net https://*.facebook.com https://*.tiktok.com https://*.tiktokw.us; style-src 'self' 'unsafe-inline' https://*.userway.org https://*.exponea.com https://*.freshchat.com https://*.facebook.net https://*.facebook.com https://*.tiktok.com https://*.tiktokw.us https://*.google.com https://*.b- strict-transport-security
max-age=63072000; includeSubDomains; preload