easypara.es
HTML metadata
Technology
- CDN
- Fastly
- CMS
- Gatsby
Third-party hosts loaded (6)
- admin-pipeline.upsun-eu-5.observability-pipeline.blackfire.io×1
- client.px-cloud.net×1
- www.easypara.co.uk×1
- www.easypara.com×1
- www.easypara.fr×1
- www.easypara.it×1
Social
Contact
- Address
- Boulevard René Cassin - 06200
DNS records live
- NS
-
- mimi.ns.cloudflare.com
- sri.ns.cloudflare.com
- MX
-
Show 6 MX records
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 10 feedback-smtp.eu-west-3.amazonaws.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=fuGkg1_HtE5T2HZpiHPYmcyH6I0Xjam5cYCz51CMT7E
Email authentication partial
- SPF
-
v=spf1 include:amazonses.com include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:itteam@easyparapharmacie.compolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlZtyWxwN1VHctGiCpzaQSaPqXUbBNzsaH0/rL/mcbO2G/F+VT87oW8xTF6ylllP+BcjLkaEqh+qW2V…
selectors probed - google:
Certificate (current)
R12
Expires in 29 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
font-src cash-f.squarecdn.com *.oney.io *.staging.oney.io fonts.gstatic.com apps.bazaarvoice.com dsf-cdn.loreal.io dev.easypara.fr dev.easypara.es dev.easypara.it dev.easypara.com dev.easypara.co.uk dev.lesalon.easypara.fr staging.easypara.fr staging.easypara.es staging.easypara.it staging.easypara.com staging.easypara.co.uk staging.lesalon.easypara.fr www.easypara.fr www.easypara.es www.easypara.it www.easypara.com www.easypara.co.uk lesalon.easypara.fr fonts.yieldify-production.com easypara.my.join-stories.com *.join-stories.com *.fontawesome.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com- strict-transport-security
max-age=31557600