interdiscount.ch
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
Social
Contact
- Address
- Bernstrasse 90, 3303, Jegenstorf, CH
DNS records live
- NS
-
- ns1.coop.ch
- ns1.ip-plus.net
- MX
-
- 10 interdiscount-ch.mail.protection.outlook.com
- TXT
-
Show 10 TXT records
abg-158-78lsuccessfactors-site-verification=ZTM0NmYxNjI3MjIyMWNhZDAwYzVhNTI3ZGNjZjgyYWU3Yjc5MTkwNWJlNGFiYzNlYTJhNTFmZmQxZGQ1Y2I3Yw==swisssign-check=E2g6mrstwufBca-ogllD3zi9NNoL+6btFA/MqUQWdq+u9MW9MXJm1I6/EQBg78EkJa5/iq2kvShephogIFZGzROlWpe6XbtVpqruo0n/4sIWYqXwg==SFMC-RayfGycEcfUhHeAU2Ln7Bmp-7_mh_BGyYh0Y-3-Jdtm-domain-verification=TmuPsBkyZ3A1eJbF8MM_9rXYgjM8A3Qwh-9TPgpsI9Eciscocidomainverification=5395b6c762a927e0087f6ee4e435c80223f7c936f4d28c85498dbce105ae794b00d1i000000gyc2eaezscaler-verification-41360891-6232025-XQc5H8ddc1MS=2B104CF3164E80C5C5D793A61CA262DB16AAE7B0
- Verified for
-
- Adobe
- Apple
- Atlassian
- DocuSign
- Meta
- Microsoft 365
- Miro
- OneTrust
- TeamViewer
Email authentication partial
- SPF
-
v=spf1 mx include:spf.o365.coop.ch include:spf.protection.outlook.com include:spf.messagelabs.com include:_spf.qemailserver.com include:_spf-dc2.successfactors.com a:service.unic24.net a:relay.claranet.de ip4:212.82.225.203 ip4:212.82.225.204 ip4:217.71.90.108 ip4:217.71.90.109 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; fo=1; ri=3600; rua=mailto:927757b0@inbox.eu.redsift.cloud; ruf=mailto:927757b0@inbox.eu.redsift.cloud;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwegsJvIyaIAMH5mvSIU5Kye2a0ATLDP+nWXQO3I4KtIw1jmgP8k3axISuTZBd6BOz487OtAqXdHiTZ…
selectors probed - selector1:
Certificate (current)
SwissSign RSA TLS OV ICA 2022 - 1
Expires in 261 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
Header values
- permissions-policy
geolocation=(self)- content-security-policy
base-uri 'self'; form-action 'self'; object-src 'none'; worker-src 'self' blob:; frame-ancestors 'self' https://*.interdiscount.ch; connect-src 'self' blob: *.bing.com *.bing.net *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.facebook.com *.googleapis.com *.google.com *.google.ch *.googletagmanager.com *.googleadservices.com *.gstatic.com *.hotjar.com *.kameleoon.io *.kameleoon.eu *.kameleoon.com mycliplister.com *.mycliplister.com *.speedcurve.com *.tiqcdn.com *.tealiumiq.com *.theadex.com *.datadome.co ct.captcha-delivery.com *.expeerly.com https://cdn.jsdelivr.net cdn.jsdelivr.net/npm/@mux/mux-player *.usercentrics.eu *.mfgroup.ch *.interdiscount.ch *.algolia.net *.algolianet.com *.algolia.io *.google-analytics.com *.analytics.google.com https://*.litix.io *.mux.com *.youtube.com *.youtube-nocookie.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.bing.com *.bing.net *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.facebook.co- strict-transport-security
max-age=31536000; includeSubDomains; preload- content-security-policy-report-only
base-uri 'self'; form-action 'self'; object-src 'none'; worker-src 'self' blob:; frame-ancestors 'self' https://*.interdiscount.ch; connect-src 'self' blob: *.bing.com *.bing.net *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.facebook.com *.googleapis.com *.google.com *.google.ch *.googletagmanager.com *.googleadservices.com *.gstatic.com *.hotjar.com *.kameleoon.io *.kameleoon.eu *.kameleoon.com mycliplister.com *.mycliplister.com *.speedcurve.com *.tiqcdn.com *.tealiumiq.com *.theadex.com *.datadome.co ct.captcha-delivery.com *.expeerly.com https://cdn.jsdelivr.net cdn.jsdelivr.net/npm/@mux/mux-player *.usercentrics.eu *.mfgroup.ch *.interdiscount.ch *.algolia.net *.algolianet.com *.algolia.io *.google-analytics.com *.analytics.google.com https://*.litix.io *.mux.com *.youtube.com *.youtube-nocookie.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.bing.com *.bing.net *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.facebook.co