les-cj.ch
HTML metadata
Technology
- Stack
- ASP.NET
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns11.infomaniak.ch
- ns12.infomaniak.ch
- MX
-
- 1 mx1-eu1.ppe-hosted.com
- 2 mx2-eu1.ppe-hosted.com
- Verified for
-
- Meta
Email authentication weak
- SPF
-
v=spf1 a:dispatch-eu.ppe-hosted.com a ip4:193.3.183.0/25 ip4:35.156.0.138 ip4:37.139.12.94 ip4:185.123.25.25 ip4:62.2.255.172 include:spf1.net4all.ch include:spf.protection.outlook.com include:spf.eu.signature365.net -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 69 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
Header values
- referrer-policy
same-origin- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(self "https://www.youtube.com" "https://www.youtube-nocookie.com" "https://player.vimeo.com"), battery=(), bluetooth=(), camera=(), captured-surface-control=*, clipboard-read=(), clipboard-write=(), compute-pressure=(), deferred-fetch=*, deferred-fetch-minimal=* ,display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(self "https://www.youtube.com" "https://www.youtube-nocookie.com" "https://player.vimeo.com"), gamepad=(), geolocation=(), gyroscope=(), hid=(), identity-credentials-get=(), idle-detection=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), on-device-speech-recognition=(), otp-credentials=(), payment=(), picture-in-picture=(), private-state-token-issuance=(), private-state-token-redemption=(), publickey-credentials-create=(), publickey-credentials-get=(), screen-wake-lock=(self "https://www.youtube.com" "https://www.youtube-nocookie.com" "https://player.vimeo.com"), serial=(), speaker-selection=- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' ; font-src 'self' data: https: ; img-src 'self' data: https: ; default-src https: 'unsafe-inline' 'unsafe-eval' ; object-src 'none' ; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com ;- strict-transport-security
max-age=31536000