echelle-europeenne.es
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- cdn.novius.net×2
- static.axept.io×1
- www.googletagmanager.com×1
Social
Contact
- Address
- st mediaQuery = window.matchMedia('(max-width: 1024
DNS records live
- NS
-
- ns-124-c.gandi.net
- ns-210-a.gandi.net
- ns-81-b.gandi.net
- MX
-
- 1 mx0.mail.ovh.net
- 100 mx3.mail.ovh.net
- 5 mx1.mail.ovh.net
- 50 mx2.mail.ovh.net
- Verified for
-
- GlobalSign
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 33 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
script-src blob: 'self' 'unsafe-eval' 'unsafe-inline' https://www.google-analytics.com https://www.googletagmanager.com https://tagmanager.google.com https://maps.googleapis.com https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.youtube.com https://connect.facebook.net https://*.clarity.ms https://d13sozod7hpim.cloudfront.net https://sibautomation.com https://serve.albacross.com/track.js https://static.hotjar.com/c/hotjar-3674392.js https://script.hotjar.com/modules.b062b42f742f840ab0c4.js https://snid.snitcher.com/8431811.js https://cdn.brevo.com/js/ https://conversations-widget.brevo.com https://conversations-widget.sendinblue.com https://cdn.snitcher.com https://cdn.by.wonderpush.com https://script.hotjar.com https://static.axept.io https://t.novius.net https://cdn.novius.net; object-src 'self'- strict-transport-security
max-age=31536000; includeSubDomains; preload