epicoeur.be
HTML metadata
Technology
- Server
- nginx
- Stack
- Java
Third-party hosts loaded (1)
- cdn.socleo.org×33
DNS records live
- NS
-
- ns11.infomaniak.ch
- ns12.infomaniak.ch
- MX
-
- 5 mta-gw.infomaniak.ch
Email authentication strong
- SPF
-
v=spf1 include:spf.infomaniak.ch -allstrict (-all) - DMARC
-
v=DMARC1; p=reject;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src https: data: *; script-src https://cdn.socleo.org https://cdn.panierlocal.org https://cdn.socleo.org http://*.google.com https://*.google.com http://*.google-analytics.com https://*.google-analytics.com https://*.apis.google.com https://*.googleapis.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net http://*.twitter.com https://twitter.com https://*.twitter.com https://*.twimg.com http://connect.facebook.net https://connect.facebook.net http://*.ak.fbcdn.net https://*.ak.fbcdn.net https://instagram.com https://www.instagram.com https://cdnjs.cloudflare.com https://unpkg.com https://js.stripe.com https://*.brevo.com https://widget.mondialrelay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' *; img-src data: blob: *; frame-ancestors 'self'; report-uri /enl/csp_report.jsp- strict-transport-security
max-age=15768000
epicoeur.be