haulotte.se

.se crawl

First seen 2026-05-22 · Last seen 2026-05-30 · ok HTTP/1.1 200 8715 ms crawled 2026-05-28

FR · 134.90.136.56 · AS198330 Xefi Lyon SAS

Reputation 67/100 wrong cert no dmarc policy

Classifying

HTML metadata

Title
Aerial work platforms: equipment for lifting people and loads · Haulotte Scandinavia
Description
Haulotte is one of the world leaders in equipment for lifting people and loads. The group designs, manufactures and markets a wide range of products, including aerial work platforms and telescopic forklift-trucks.
Language
en
Canonical
https://www.haulotte.se/en_SE/
Translations
  • en ×9
  • es ×4
  • fr ×2
  • de
  • it
  • ja
  • nl
  • pl
  • pt
  • zh

Technology

CDN
Azure Front Door
PHP
8.1.34 end of life
Stack
PHP
Analytics
  • Google Tag Manager
Third-party hosts loaded (22)
  • haulotte.ephoto.fr×5
  • www.haulotte-africa.com×2
  • www.haulotte.pl×2
  • www.googletagmanager.com×1
  • www.haulotte-chile.com×1
  • www.haulotte-usa.com×1
  • www.haulotte.ae×1
  • www.haulotte.cn×1
  • www.haulotte.co.uk×1
  • www.haulotte.com×1
  • www.haulotte.com.ar×1
  • www.haulotte.com.au×1
  • www.haulotte.com.br×1
  • www.haulotte.com.es×1
  • www.haulotte.com.mx×1
  • www.haulotte.de×1
  • www.haulotte.fr×1
  • www.haulotte.in×1
  • www.haulotte.it×1
  • www.haulotte.jp×1
  • www.haulotte.nl×1
  • www.haulotte.sg×1

Social

DNS records live

NS
  • dns2.french-connexion.com
  • dns70.domaine.fr
  • ns1-05.azure-dns.com
  • ns2-05.azure-dns.net
  • ns3-05.azure-dns.org
  • ns4-05.azure-dns.info
MX
  • 10 mail.haulotte.se
TXT
  • proxy-ssl.webflow.com

Email authentication weak

SPF
v=spf1 +a +mx -all +a:dns70.domaine.fr
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current) wrong cert

Sectigo Public Server Authentication CA OV R36
from 2025-09-19 to 2026-10-21
Expires in 142 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://www.haulotte.se/en_SE/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer, strict-origin-when-cross-origin
x-frame-options
sameorigin
x-content-type-options
nosniff
content-security-policy
default-src 'self'; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://maps.googleapis.com https://api.ipify.org https://*.googleoptimize.com https://*.g.doubleclick.net https://*.google.com https://*.claspo.io https://*.ads.linkedin.com; font-src 'self' 'unsafe-inline' data: https://fonts.gstatic.com; frame-src 'self' * blob:; img-src 'self' 'unsafe-inline' data: https://haulotte.ephoto.fr https://maps.googleapis.com https://maps.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://*.googleoptimize.com https://*.g.doubleclick.net https://*.google.com https://*.ads.linkedin.com https://recruitingbypaycor.com https://www.google.fr https://www.google.com; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://*.google-analytics.com https://ssl.google-analytics.com https://maps.googleapis.com https://static.addtoany.com https://code.jquery.com https://haulotte-dam.ephoto.fr https:

Links to (8)

Linked from (2)