eazle.fr
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- nexus.ensighten.com×2
- www.googletagmanager.com×1
Registration
- Registrar
- CSC CORPORATE DOMAINS INC.
- Created
- 2022-12-16
- Expires
- 2026-12-16 209 days left
- Updated
- 2025-12-17
- Name servers
-
- dns1.cscdns.net
- dns2.cscdns.net
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 0 eazle-fr.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_u.eazle.fr._spf.smart.ondmarc.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; sp=reject; rua=mailto:515c7f87@inbox.ondmarc.com; ruf=mailto:515c7f87@inbox.ondmarc.com; adkim=r; aspf=r; fo=1; rf=afrf; ri=3600policy: reject (enforced) · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnpzWtBwzjvubfZn/nYrAP+gpKU6abntZY0tT+yfuvO6Xs/Yk04AEw49cXiB+x228UFlN2mn79CC6h5…
selectors probed - selector1:
Certificate (current)
R12
Expires in 75 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
ALLOWALL- permissions-policy
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), usb=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https: data:; script-src 'self' *.cloudflare.com *.googleapis.com *.newrelic.com *.nr-data.net *.contentsquare.net *.abtasty.com *.google-analytics.com *.googletagmanager.com *.google.com *.gstatic.com *.epoq.de *.ensighten.com *.slgnt.eu data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' *.cloudflare.com *.googleapis.com *.google.com *.abtasty.com *.epoq.de *.google-analytics.com *.doubleclick.net *.contentsquare.net *.ensighten.com *.nr-data.net *.slgnt.eu; worker-src 'self' blob:; style-src 'self' *.abtasty.com 'unsafe-inline'; font-src 'self' *.abtasty.com blob: data:; object-src 'none'; img-src 'self' https: *.abtasty.com *.amazonaws.com data: blob:; upgrade-insecure-requests;