gbl.com

.com crawl

First seen 2026-05-28 · Last seen 2026-05-31 · ok HTTP/1.1 200 381 ms crawled 2026-05-31

FR · 152.228.180.94 · AS16276 OVH SAS

Reputation 100/100

Classifying

HTML metadata

Title
GBL - Investment holding
Description
Groupe Bruxelles Lambert (GBL) is an established investment holding company. Leading investor in Europe, GBL focuses on long-term value creation and relies on a stable and supportive family shareholder base.
Language
en
Generator
Drupal 11 (https://www.drupal.org)
Canonical
https://www.gbl.com/en
Translations
  • en
  • fr
  • nl

Open Graph

url
https://www.gbl.com/en/node/2
title
GBL - Investment holding | GBL
site name
GBL
description
Groupe Bruxelles Lambert (“GBL”) is an established investment holding company, with over seventy years of stock exchange listing, a net asset value of €13 billion and a market capitalization of €10 billion at the end of March 2026. GBL is a leading investor in Europe, focused on long-term value creation and relying on a stable and supportive family shareholder base.

Technology

CMS
Drupal
Analytics
  • Google Tag Manager
Fonts
  • Adobe Fonts

Third-party hosts loaded (3)

  • policy.app.cookieinformation.com×1
  • use.typekit.net×1
  • www.googletagmanager.com×1

Contact

Email
Phone
Address
Avenue Marnix, B-1000, Brussels, Brussels, Belgium

Registration

Registrar
Combell NV
Created
1997-07-09
Expires
2026-07-08 37 days left
Updated
2023-04-25
Name servers
  • ns3.combell.net
  • ns4.combell.net

DNS records live

NS
  • ns1.combell.eu
  • ns3.combell.net
  • ns4.combell.net
MX
  • 0 gbl-com.mail.protection.outlook.com
TXT
  • atlassian-sending-domain-verification=8646ae38-2be8-4331-ba88-2e4081275579
Verified for
  • Apple
  • Atlassian
  • Google
  • Microsoft 365
  • Zoom

Email authentication strong

SPF
v=spf1 mx ip4:152.228.180.108/32 ip4:217.117.39.176/28 ip4:152.228.180.94/32 ip4:35.180.128.154/32 include:servers.mcsv.net include:spf.protection.outlook.com include:spf.exclaimer.net -all
strict (-all)
DMARC
v=DMARC1;p=reject;rua=mailto:bdea94f0@mxtoolbox.dmarc-report.com;ruf=mailto:bdea94f0@forensics.dmarc-report.com; fo=1:d:s
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuG65AIUs+S1+NIQzCjVjIRyeXBLkMK6uaETA9fhKH+5W+QOf1mjukQw/1A7TGy1adDmWiX9iamAa3g…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5L0jMOhadx5bsIZ7mIp0S3n4NttVFooB7ffbwxs77yaw9JukxW678E8/anuzQpaazxKraxvEZ3r/f5…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

GandiCert
from 2025-05-22 to 2026-06-23
Expires in 22 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.gbl.com/en

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
  • weak content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN, SAMEORIGIN
x-content-type-options
nosniff, nosniff
content-security-policy
default-src 'self' https: ws: wss: data: blob: 'unsafe-inline'; script-src blob: 'self' 'unsafe-inline' 'unsafe-eval' https://*.matomo.cloud https://*.cookielaw.org https://*.facebook.com https://*.hotjar.com https://*.licdn.com https://reservations.tablebooker.com https://*.doubleclick.net https://www.googleadservices.com https://static.addtoany.com https://*.tiktok.com https://embed.typeform.com https://cdn.syndication.twimg.com https://*.twitter.com https://*.getclicky.com https://chat.sendinblue.com https://sibautomation.com https://code.createjs.com https://use.typekit.net https://vjs.zencdn.net https://*.cookiebot.com https://cdn.jsdelivr.net https://s7.addthis.com https://*.googleapis.com https://*.list-manage.com https://unpkg.com https://code.jquery.com https://js.stripe.com https://ws.sharethis.com https://cdnjs.cloudflare.com https://connect.facebook.net https://*.google-analytics.com https://cdn.ckeditor.com https://policy.app.cookieinformation.com https://s3.amazonaws.com
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (1)

Linked from (1)