foodora.se
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (5)
- micro-assets.foodora.com×46
- images.deliveryhero.io×2
- www.googletagmanager.com×2
- app.usercentrics.eu×1
- cdnjs.cloudflare.com×1
DNS records live
- NS
-
- clint.ns.cloudflare.com
- gwen.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
CKO=cli_u7wxnwvsmqyupia3x77hf42bqejamf-site-verification=hFVztq8O172nNRrV5aNV0Qamazonses:EkIHhAingM13nYtPa6rOSgQO+n5tLaKdalSyej6XcjI=
- Verified for
-
- Adobe
- Anthropic
- Atlassian
- DocuSign
- Microsoft 365
- Smartsheet
- TeamViewer
- Zoom
Email authentication partial
- SPF
-
v=spf1 ip4:217.110.53.72 include:_spf.google.com include:mg-spf.greenhouse.io include:mail.zendesk.com include:amazonses.com include:eu.mailgun.com include:_spf.salesforce.com include:aspmx.pardot.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:d5ea1768a1c4993@rep.dmarcanalyzer.com; ruf=mailto:d5ea1768a1c4993@for.dmarcanalyzer.com; fo=1;policy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzoEF7NAYOxtqheqbdDPiHDUuLJnIO0/X51y2yKyK3AubnYOfaY1pjcuy8kmhcJHVk50RKf7D89Yrxd… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuH7MuqbAWMKyWsYAtgrWje6TlGfv6l0VbBkgBWvOqHnNOeIi7IQi0zW9EBF/x9cOd+dWciI7YhxGtoJFmw0WHxyfgtI… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvya5Z9gkMjM/luIt2HK8CxosN9cMVhYo63JcD52sqpjXkacMr2pKaZxuRM8PmBW+kODph0nkcp05Ozu3fo… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxz2WGVyyH+kITKhfvgz7PjJH77wkLu9Wjw96KmC2tl7ZDnwbF2prZqVU2aype3rxm4WyphNXik4NsR0Ocb…
selectors probed - google:
Certificate (current)
R12
Expires in 81 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self' *.incognia.com *.icg-in.com https://micro-assets.foodora.com; connect-src 'self' data: *.ingest.sentry.io *.fd-api.com *.deliveryhero.net *.deliveryhero.io https://d3t78t62rc3tw1.cloudfront.net https://images.dhmedia.io *.googleapis.com *.gstatic.com *.braze.com *.usercentrics.eu *.googletagmanager.com *.google-analytics.com stats.g.doubleclick.net *.incognia.com *.icg-in.com *.icg-in.info wss://*.incognia.com wss://*.icg-in.info wss://*.icg-in.com https://www.accounts.google.com https://adservice.google.com *.adservice.google.com https://adservice.google.com/pagead/regclk googleads.g.doubleclick.net stats.g.doubleclick.net *.googleadservices.com https://analytics.google.com *.analytics.google.com https://api.avo.app *.px-cloud.net *.hotjar.io *.googlesyndication.com *.google.at *.google.bd *.google.cy *.google.cz *.google.ch *.google.fi *.google.fr *.google.hu *.google.jp *.google.hk *.google.la *.google.my *.google.nl *.google.no *.google.ph *.google.pk *.google.pl- strict-transport-security
max-age=5184000; includeSubDomains
Linked from (4)
- vegabar.se×1
- yoi.se×1
- tewesdeli.se×1
- elbirria.se×1