gameloft.com
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Gandi SAS
- Created
- 1999-04-08
- Expires
- 2028-04-08 688 days left
- Updated
- 2026-02-12
- Name servers
-
- eve.ns.cloudflare.com
- yoxall.ns.cloudflare.com
DNS records live
- NS
-
- eve.ns.cloudflare.com
- yoxall.ns.cloudflare.com
- MX
-
- 10 mail02.gameloft.com
- 10 mail03.gameloft.com
- TXT
-
Show 11 TXT records
have-i-been-pwned-verification=24cb3133a6abd999153488dc64abb0deasn-verification=6faa9e28d1d8326ce96dc1dad702e3e0d05c7d63bfb88685d789230381a9fc93unity-sso-verification=03dd1518-03f9-4672-ad16-68898f219eaetiktok-developers-site-verification=RdY1qyUJWFmuNYiTizbTxjhLOVv1qoa5MS=CA571F175464FEB48F2EAD669CFF06A2A5F5496AMS=8D8DC21A8FA329988B2DD28DAED1685921B8AFC2bysfwv71j91p2lqglkrshj7frlmn757ktiktok-developers-site-verification=5r7KhkJZhTg1bm0jVWLoZJIoJby3KERUrx2BLPG2g1MGSQzdsUdtKkgIOpd9WAR2Ugy9k9SAR3oKDEnNAvWLg1i2oY4PoZB7z980szdu0wSJnaQQarDjaQ==d06cd2ed3e379d3168e27c1d73f8a55f5c99f0d317d3d9f7db7ebcd0f6b2a2a7tiktok-developers-site-verification=sPECG1NSVhOm1RleGCEswiafa53MS3zv
- Verified for
-
- Airtable
- Apple
- Atlassian
- DocuSign
- Microsoft 365
- Miro
- MongoDB
Email authentication strong
- SPF
-
v=spf1 include:_spf.gameloft.com include:_spf.google.com include:emsd1.com include:146010223.spf01.hubspotemail.net include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:7b4a01e2@mxtoolbox.dmarc-report.com; ruf=mailto:7b4a01e2@forensics.dmarc-report.com;policy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCw0Ih9xbsSwj3GqvqToAiHrbwe4y6MNTdyhcui5WW1eS2jSr6iUIaZWdUCEaVuA/c9JAkQcuF5pDln655/k6… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - google:
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 133 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=()- x-content-type-options
nosniff- content-security-policy
script-src 'self' gameloft.com *.gameloft.com gameloft.org *.gameloft.org *.google.com *.gstatic.com *.google-analytics.com *.youtube.com *.doubleclick.net *.amazonaws.com *.googletagmanager.com *.privacy-center.org *.crazyegg.com *.tiktok.com *.ads-twitter.com *.facebook.net *.singular.net *.gsght.com *.cloudflare.com 'unsafe-eval' 'unsafe-inline';- strict-transport-security
max-age=31536000; includeSubDomains; preload