cotoit.fr
HTML metadata
Technology
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- cdn.dexem.net×1
- fonts.googleapis.com×1
- gmpg.org×1
- pqv748rx3t.kameleoon.io×1
Social
Contact
- Phone
- Address
- Boulevard Rocheplatte45000
Registration
- Registrar
- OVH
- Created
- 2018-01-31
- Expires
- 2027-01-31 256 days left
- Updated
- 2026-02-28
- Name servers
-
- dns11.ovh.net
- ns11.ovh.net
DNS records live
- NS
-
- dns11.ovh.net
- ns11.ovh.net
- MX
-
- 0 cotoit-fr.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
iYvt3IRexdHZ1Nm6p9A006Ei0kNVPCvFIwLDZkjjJXSdF5xIIGxa1pFMKjpZsqAv/2WDqE1yxN/IbudY9cqmyQ==google-site-verification=vOVi8D1ms2UjJzt0398EWB5TbC4vo3r6Oawtpwz4_58google-site-verification=x0EPdX6AFkEvkvmlgsfpVuVt_NLVPcWJKUWcU05ICqoMS=ms71660114zoho-verification=zb64332733.zmverify.zoho.eu1|www.cotoit.frbrevo-code:6b6c0e4ca69121ce272ba0e3770c67b5
Email authentication strong
- SPF
-
v=spf1 ip4:185.57.53.253 include:spf.protection.outlook.com include:eu.zcsend.net ip4:149.202.221.50 ip4:51.68.36.163 ip4:141.94.218.167 include:one.zoho.eu include:spf.brevo.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; rua=mailto:abuse@squarehabitat.fr; adkim=r; aspf=rpolicy: reject (enforced) · sp=reject - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCLMT5ZVldWG9Pt/u4H64P6wlI95kZ5nhtFH2k/ugF8jxEsaQ0h9K8zb29dnBMixRpEN1+7MHh6EoEG36gYdD… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmyZL0h9VzyURtHQJLH5wv1FxIIh39fadS+nnSbPWIhq6RmkVoXjN8rM3fcS/2nX4IHe/QYgb8tWdmT… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - google:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 183 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
geolocation=(), midi=(), sync-xhr=(), accelerometer=(), gyroscope=(), magnetometer=(), camera=(), fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
default-src https: 'nonce-abc123'; frame-src blob: https:; connect-src 'self' *.cotoit.fr cotoit.fr *.matomo.cloud *.google-analytics.com *.analytics.google.com *.g.doubleclick.net coti-zcmp.maillist-manage.eu *.immodvisor.com *.googletagmanager.com *.bing.com next-dexem.netdna-ssl.com *.google.com *.google.fr *.googlesyndication.com *.privacy-center.org yoast.com *.air360tracker.net *.kameleoon.io *.kameleoon.com *.ca-immobilier.fr *.ipify.org; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.immodvisor.com *.zohostatic.eu; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.air360tracker.net; script-src-elem 'self' 'unsafe-inline' https: 'unsafe-inline' googletagmanager.com *.air360tracker.net; worker-src blob: 'self'; img-src data: https: blob:; font-src 'self' data: fonts.gstatic.com *.immodvisor.com 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https: 'unsafe-inline' *.kameleoon.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload