jet2carhire.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- CMS
- Gatsby
Third-party hosts loaded (4)
- cars.cartrawler.com×46
- ctimg-supplier.cartrawler.com×10
- ctimg-svg.cartrawler.com×4
- ctimg-mcore.cartrawler.com×3
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 2007-04-27
- Expires
- 2027-04-27 342 days left
- Updated
- 2026-04-23
- Name servers
-
- ns1.netnames.net
- ns2.netnames.net
- ns5.netnames.net
- ns6.netnames.net
DNS records live
- NS
-
- ns1.netnames.net
- ns2.netnames.net
- ns5.netnames.net
- ns6.netnames.net
- MX
-
- 100 maillba.jet2.com
- 5 mailncl.jet2.com
- TXT
-
LC/u1ixEXMP/ol2HP45O3hA0VG8go39u4OMkPv2uxus=google-site-verification=oJdo6w2o-QF8BXygZEofaOpBUvHMEURXszKiiIgeMfw
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 101 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(self "https://goo.gl"), gyroscope=(), magnetometer=(), microphone=(), payment=(self "https://*.cartrawler.com"), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.cartrawler.com *.analytics.google.com *.google-analytics.com *.google.com *.googletagmanager.com *.clarity.ms google.com www.wepowerconnections.com www.awin1.com the.sciencebehindecommerce.com *.doubleclick.net fonts.gstatic.com maps.googleapis.com cdn.cookielaw.org o1008192.ingest.sentry.io cdn.edgetier.com vc.hotjar.io content.hotjar.io paymentform-staging.cartrawler.net data: ws: ws.hotjar.com arthur.edgetier.com *.onetrust.com *.bing.com *.jscrambler.com v6.exchangerate-api.com analytics.skyscanner.net *.quantcount.com *.quantserve.com; style-src 'self' 'unsafe-inline' *.cartrawler.com *.bing.com fonts.googleapis.com cdn.edgetier.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.cartrawler.com *.google-analytics.com *.clarity.ms the.sciencebehindecommerce.com googleads.g.doubleclick.net www.dwin1.com *.bing.com cdn.cookielaw.org cdn.edgetier.com cdn.cookie-script.com script.hotjar.com static.hotjar.com maps.googleapis.com www.googletagmanager.com www.googl- strict-transport-security
max-age=31536000; includeSubDomains; preload