ds-orleans.fr
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Ads
-
- Meta Pixel
- Cookie consent
-
- Iubenda
- Fonts
-
- Google Fonts
Third-party hosts loaded (14)
- webspark-assets.dealerk.com×37
- cdnwp.dealerk.com×27
- cdn-datak.motork.net×17
- cdn.iubenda.com×5
- bam.nr-data.net×2
- cdn.dealerk.it×2
- connect.facebook.net×2
- fonts.googleapis.com×2
- fonts.gstatic.com×2
- js-agent.newrelic.com×2
- maps.googleapis.com×2
- www.facebook.com×2
- gmpg.org×1
- livechat.ekonsilio.io×1
Social
Contact
- Phone
- Address
- Rue de la Bergeresse, 45160
Registration
- Registrar
- OVH
- Created
- 2017-10-18
- Expires
- 2026-10-18 151 days left
- Updated
- 2025-11-30
- Name servers
-
- dns15.ovh.net
- ns15.ovh.net
DNS records live
- NS
-
- dns15.ovh.net
- ns15.ovh.net
- MX
-
- 1 mx.verifmail.fr
- TXT
-
4|http://parking.axn.fr/
Email authentication weak
- SPF
-
v=spf1 include:sendgrid.net ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 81 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
magnetometer=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' *.dealerk.com *.motork.io *.drivek.com *.drivek.fr *.drivek.de *.drivek.it *.drivek.es *.drivek.co.uk *.dealerk.fr *.dealerk.de *.dealerk.it *.dealerk.es *.dealerk.co.uk *.jsdelivr.net *.vimeo.com data: blob: *.googletagmanager.com *.iubenda.com *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.google.com *.googleadservices.com *.googleoptimize.com *.googlesyndication.com *.googleapis.com *.gstatic.com *.google.it *.google.es *.google.be *.google.fr *.google.nl *.google.de *.google.pt *.google.co.ma *.google.co.uk *.google.cat *.nr-data.net *.unpkg.com *.newrelic.com *.youtube.com *.emlsend.com *.acumbamail.com *.linkedin.com *.oribi.io *.snapchat.com *.tapad.com *.sc-static.net *.tiktok.com *.twitter.com *.privacy-center.org *.matomo.cloud *.ekonsilio.io *.ekonsilio.com wss://livechat.ws.ekonsilio.io *.wisepops.net *.wisepops.com *.hotjar.com *.teads.tv *.greenbureau.com *.vivavi.fr *.bdk-bank.io *.bnpparibas-pf.c- strict-transport-security
max-age=31536000; includeSubdomains;