emosson.ch
HTML metadata
Technology
- Server
- nginx
- jQuery
- 2.2.4 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- www.googletagmanager.com×1
- www.hemmer.ch×1
Contact
- Phone
- Address
- Centrale de la Bâtiaz, 1920, Martigny, VS, Suisse
DNS records live
- NS
-
- whns.komodo.ch
- whs03.komodo.ch
- MX
-
- 10 emosson-ch.mail.protection.outlook.com
Email authentication weak
- SPF
-
v=spf1 a mx include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 55 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.g.doubleclick.net *.google-analytics.com *.gstatic.com; script-src 'self' 'unsafe-inline' *.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.jquery.com unpkg.com *.cloudflare.com theodia.org *.openweathermap.org 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.google.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.googleapis.com *.gstatic.com; base-uri 'self'; frame-src 'self' *.google.com *.theodia.org *.youtube-nocookie.com *.youtube.com *.doubleclick.net theodia.org valleedutrient.roundshot.com; style-src 'self' 'unsafe-inline' data: *.googleapis.com *.googletagmanager.com *.theodia.org *.typekit.net cdnjs.cloudflare.com cdn.jsdelivr.net 'report-sample'; connect-src 'self' *.google.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.doubleclick.net *.openweathermap.org; font-src 'self' *.google.com *.goo