esb.ie
HTML metadata
Technology
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×1
- code.jquery.com×1
DNS records live
- NS
-
- bogben.netsource.ie
- ice.netsource.ie
- iridium.netsource.ie
- MX
-
- 10 mx1.hc1801-12.c3s2.iphmx.com
- 10 mx2.hc1801-12.c3s2.iphmx.com
- TXT
-
Show 12 TXT records
CcAQT8qMWhELEO6YPHk9f/bq92+6GnrnDXuEDsrFVfSNQxkNeeJTMacWHkA2xncOgmbLHvELF4zhNa+rLCcO3A==1m3cv94o2a2knv704uo31vh1f77fgfgph1el1f6dugf0vlqcoqfe848uef88mkb5d0qpip23vsrh3mddmp1ii3c0e05q6tq61s4hp8fmitknkc6lp5140kcepg365a4hj8j2kmk703evp8puto1k5rm94pd3pjr4q2bjq06sqkfaf75ve38lpruotdv19d4lvoquvejisq9anqg9_awb7frv9qipqqp4h0z1k10n2vvk6so5nvqq4p4s8k0tjmzt2tqzq7v1s3df5s6rA7DC66F37150C0CEC15A477E813803DF57540631C239E9D980707DE95B5EA0CB
- Verified for
-
- Apple
- DocuSign
- Mailgun
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; pct=100; fo=1; ri=3600; rua=mailto:a4714750@inbox.ondmarc.com,mailto:dmarcnotifications@esb.ie; ruf=mailto:a4714750@inbox.ondmarc.com,mailto:dmarcnotifications@esb.ie;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDElxqFlm4wD1O3TvIK+zNeqFC5vN4EqRSQBNKdG3vQ8ogZHhD9qs+1lSEGnJajFY612E3OY7bhngh4kqeJJ5… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv0OqUR1NouZt1P5UMcpKjwCUXdMNiUZYRg/nMNremqSsG/XeLMzpfvVsRV7bnoX4NbbgskrNy1JLzv8Yuj… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDRj9+2EgqY/w6M9G/wT8qeytaWtBX0nQsAOvSyTFkOScCoLWdl6HU9eAx2mcPBstMd6/P+ZyPnPSQb9GgFRwGPzg…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 313 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src www.google.com apis.google.com connect.facebook.net ajax.aspnetcdn.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com platform.linkedin.com *.vo.msecnd.net code.jquery.com www.googleapis.com maps.googleapis.com www.gstatic.com maps.gstatic.com maps.google.com www.googleadservices.com googleads.g.doubleclick.net www.youtube.com www.google-analytics.com https://www.youtube.com/iframe_api www.twimg.com https://dec.azureedge.net/ www.en25.com cdn.cookielaw.org www.googletagmanager.com browser-update.org www.addthis.com snap.licdn.com sc-static.net analytics.tiktok.com static.ads-twitter.com analytics.twitter.com myaccount.esbecars.com http://10.80.46.60:15871 cdnjs.cloudflare.com tr.snapchat.com https://cdn.edgetier.com/ 'self' js.hs-scripts.com js.hs-analytics.net js.hs-banner.com js.hsleadflows.net forms.hubspot.com js.hscollectedforms.net cdn.ampproject.org web-chat.nativechat.com *.eloqua.com *.en25.c- strict-transport-security
max-age=31536000; includeSubDomains