immovalor.fr
HTML metadata
Technology
- Server
- nginx
- Cookie consent
-
- OneTrust
Third-party hosts loaded (1)
- cdn.cookielaw.org×1
Registration
- Registrar
- CSC CORPORATE DOMAINS INC.
- Created
- 2000-08-15
- Expires
- 2027-04-13 328 days left
- Updated
- 2026-04-14
- Name servers
-
- ns1.allianz.com
- ns2.allianz.com
- ns3.allianz.de
- ns4.allianz.de
- ns5.az-ip.net
- ns6.az-ip.net
DNS records live
- NS
-
- ns1.allianz.com
- ns2.allianz.com
- ns3.allianz.de
- ns4.allianz.de
- ns5.az-ip.net
- ns6.az-ip.net
- MX
-
- 50 mxa-00137205.gslb.pphosted.com
Email authentication strong
- SPF
-
v=spf1 a mx ptr ip4:164.132.171.177/32 include:spfa.alinto.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:Rua-allianz@allianz.com; ruf=mailto:Ruf-allianz@allianz.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 41 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
DENY- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https://openam.azfr.allianz https://code.jquery.com https://cdn.cookielaw.org https://optanon.blob.core.windows.net https://www.googletagmanager.com https://www.youtube.com fonts.googleapis.com fonts.gstatic.com geo0.ggpht.com geo1.ggpht.com geo2.ggpht.com geo3.ggpht.com lh3.ggpht.com www.gstatic.com www.immovalor.fr www.youtube-nocookie.com maps.googleapis.com maps.gstatic.com player.vimeo.com privacyportal-de.onetrust.com releases.wagtail.io stats.g.doubleclick.net www.google-analytics.com www.google.com www.google.fr www.gravatar.com immovalor.containers.piwik.pro immovalor.piwik.pro tile.openstreetmap.org; report-uri /api/csp_report/- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin