heinekenireland.ie
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (6)
- cdn.jsdelivr.net×4
- cdnjs.cloudflare.com×3
- videoengine.investisdigital.com×2
- www.googletagmanager.com×2
- cdn.cookielaw.org×1
- static.cloudflareinsights.com×1
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- Verified for
-
- GlobalSign
Email authentication no MX
- SPF
-
v=spf1 include:_u.heinekenireland.ie._spf.smart.ondmarc.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; sp=reject; rua=mailto:515c7f87@inbox.ondmarc.com; ruf=mailto:515c7f87@inbox.ondmarc.com; adkim=r; aspf=r; fo=0; rf=afrf; ri=3600policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
Corporation Service Company RSA OV SSL CA
Expires in 36 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' edge.api.brightcove.com viz.tools.investis.com *.media.brightcove.com cdn.jsdelivr.net dev-api.investisdigital.com api.investisdigital.com dev-assets.investisdigital.com assets.investisdigital.com qaotp.tools.investisdigital.com blob: maps.googleapis.com *.nr-data.net *.analytics.google.com *.google.com *.google-analytics.com *.amazonaws.com *.myidx.cloud; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com ict.infinity-tracking.net www.gstatic.com viz.tools.investis.com www.google.com maps.googleapis.com maps.google.com www.linkedin.com ajax.googleapis.com pi.pardot.com bam.nr-data.net *.googletagmanager.com *.google-analytics.com sjs.bizographics.com connect.facebook.net *.jquery.com irs.tools.investis.com *.hotjar.com px.ads.linkedin.com d2wy8f7a9ursnm.cloudfront.net ssl.p.jwpcdn.com js-agent.newrelic.com cdn.jsdelivr.net edge.api.brightcove.com *.googleapis.com www.youtube.com youtube.com s.ytimg.com unpkg.com *.investis-live.com dev-api.investis- strict-transport-security
max-age=15552000; includeSubDomains; preload