festool.pl
HTML metadata
Technology
- Analytics
-
- Google Analytics
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (9)
- media.cdn.festool.io×44
- assets.cdn.festool.io×15
- cdn.jsdelivr.net×13
- app.usercentrics.eu×3
- privacy-proxy.usercentrics.eu×2
- www.google-analytics.com×2
- api.usercentrics.eu×1
- js.stripe.com×1
- walls.io×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.netnames.net
- ns2.netnames.net
- ns5.netnames.net
- ns6.netnames.net
- MX
-
- 10 forward.tooltechnicsystems.com
- TXT
-
facebook-domain-verification=1aapm5yrkf0wlo7flrapv9bgc3xnoe
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: amazon-adsystem.com *.amazon-adsystem.com paa-reporting-advertising.amazon *.paa-reporting-advertising.amazon *; frame-ancestors 'self' ekat.festool.de *.festool.com- strict-transport-security
max-age=31536000; includeSubDomains
Links to (7)
- apple.com×1
- facebook.com×1
- festool.de×1
- google.com×1
- instagram.com×1
- linkedin.com×1
- youtube.com×1