imocarwash.com
HTML metadata
Technology
- CDN
- Cloudflare
- jQuery
- 2.1.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- ajax.aspnetcdn.com×2
- cdn.jsdelivr.net×1
- www.googletagmanager.com×1
Registration
- Registrar
- Gandi SAS
- Created
- 2003-04-25
- Expires
- 2027-04-25 325 days left
- Updated
- 2026-03-25
- Name servers
-
- a.dns.gandi.net
- b.dns.gandi.net
- c.dns.gandi.net
DNS records live
- NS
-
- a.dns.gandi.net
- b.dns.gandi.net
- c.dns.gandi.net
- MX
-
- 0 imocarwash-com.mail.protection.outlook.com
- Verified for
-
- Apple
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.netsolmail.net ip4:54.77.108.146 ip4:34.251.161.242 include:servers.mcsv.net include:mail.knack.com include:mail.zendesk.com include:email.chargebee.com ip4:86.188.139.50 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarcimouk@imo-carwash.co.uk; ruf=mailto:dmarcimouk@imo-carwash.co.ukpolicy: quarantine - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCRN5fnd5+d7rvTHtg5QGYzNaTVKfoVTGtwquRYw0m5uehtiA/LQ+bQx9AjIQr85x+/hizTJbNmsUJwmrpHl… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7rIxbqK6umdN5Hry4Wb4uve+4B8ZBaBhaJ76x418G5qCgjwKKELIgOi3IFboTOkuPaFB1FmAtdSg19mXO5… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtiPH1Cnr+KFNdtiHQKcPC/GLtbibLoiyk1po3d2RsSKNZNvouGRZL2ufP5I4ibUyetEl2yt4F1CiFRSVvH…
selectors probed - selector1:
Certificate (current)
WR3
Expires in 84 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:; worker-src 'self' blob:;- strict-transport-security
max-age=10886400; preload