foodji.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (7)
- cdn.prod.website-files.com×129
- js-eu1.hsforms.net×2
- www.googletagmanager.com×2
- assets.prd.heyflow.com×1
- d3e54v103j8qbb.cloudfront.net×1
- hubspotonwebflow.com×1
- js.hsforms.net×1
Social
Contact
- Phone
- Address
- München, DE
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2007-01-19
- Expires
- 2027-01-19 245 days left
- Updated
- 2025-12-15
- Name servers
-
- ns-1518.awsdns-61.org
- ns-1756.awsdns-27.co.uk
- ns-349.awsdns-43.com
- ns-952.awsdns-55.net
DNS records live
- NS
-
- ns-1518.awsdns-61.org
- ns-1756.awsdns-27.co.uk
- ns-349.awsdns-43.com
- ns-952.awsdns-55.net
- MX
-
- 0 foodji-com.mail.protection.outlook.com
- TXT
-
Show 10 TXT records
bw=lXz6rg7IFM6frGYdP9cxtCtXPlwgF0w3TrUG6dtcOdHFgoogle-site-verification=b0HYG014ykRmnWKldOq47CLc8K8Jhf_6oTW_fK7oaVomiro-verification=4b7f2fe2d0d43564c6c028ac4b4806887e084bc2openai-domain-verification=dv-Oh2sCjqcrC2DkuSjJDCEkhWzproxy-ssl.webflow.comtwilio-domain-verification=75458dcba291a8c6a0c35e6773604cb2airtable-verification=2e71f5a46a625ce35608b23db6278b4capple-domain-verification=k4zMC9UzEOg9AeZ0atlassian-domain-verification=a4G4y8o0um7CziDsg/7RZcGAltng8HldYwXtMmfc65YIgqWWZ4hneNDGCIGQpt1Datlassian-sending-domain-verification=b117a9d4-c15d-4a46-bf57-3b23375a5dac
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:amazonses.com include:142878914.spf10.hubspotemail.net include:_spf.salesforce.com include:spf.sendinblue.com include:sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:dmarc@mailinblue.com!10m,mailto:rua-import-31259@sendforensics.com; ruf=mailto:dmarc@mailinblue.com!10m,mailto:ruf-import-31259@sendforensics.com; fo=1; rf=afrf; pct=100; ri=86400policy: quarantine · sp=quarantine - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzPKiYZhk62Q+CFQp7YOoDb0VsGDE7hX4TPBhiDIoaYyQ46rPoxFZj0nGPT/WUDW3MOmtf3l1II43q7… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkhTGxKb2k1ZcFuwkNMb94s0U30/DHJdaB/iYauoYGvHEceBSus2L4LdV+7zjUKa7NL9N4JWXESjGAB8OJ78… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApmtIQt12f7Mx4f75+57fjO8rR2cDYNvW6duwJgeS2EI72+DlOngyq8QHrSJH4CYCYDe3LfHGhzlJA2PIkY… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6VrjnVrbYuh7zU+5Wp/MLVW72G692wU2rDceFPumZB2Haroexyc89GpHgd9Q0Avoas+WrErHr0HH0RuoCZoCvNx…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M01
Expires in 262 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.bing.com *.bing.net *.clarity.ms *.cookiebot.com *.foodji.com *.googletagmanager.com googletagmanager.com *.heyflow.cloud *.heyflow.com *.hotjar.com *.hotjar.io *.hs-analytics.net *.hs-banner.com *.hs-collectedforms.net *.hs-scripts.com *.hsadspixel.net *.hubspot.com *.matomo.cloud *.usemessages.com assets-cdn.ziggeo.com cdnjs.cloudflare.com cdn.jsdelivr.net cdn.prod.website-files.com cdn.weglot.com connect.facebook.net d3e54v103j8qbb.cloudfront.net googleads.g.doubleclick.net hubspotonwebflow.com *.hscollectedforms.net *.hsforms.net *.hsforms.com js.zi-scripts.com jobs-widget.recruiteecdn.com pagead2.googlesyndication.com sc.lfeeder.com snap.licdn.com www.facebook.com www.google.com www.googleadservices.com *.saltfish.ai darkvisitors.com google.com recaptcha.net www.gstatic.com; img-src 'self' data: *.ads.linkedin.com *.linkedin.com *.analytics.google.com *.bing.com *.bing.net *.clarity.ms *.foodji.com *.googl- strict-transport-security
max-age=63072000; includeSubDomains; preload