lesbonsrestes.fr
HTML metadata
Technology
- Server
- o2switch-PowerBoost-v3
- CMS
- WordPress
Third-party hosts loaded (5)
- scontent-cdg4-2.xx.fbcdn.net×7
- scontent-cdg4-1.xx.fbcdn.net×3
- sibforms.com×2
- challenges.cloudflare.com×1
- scontent-cdg6-1.xx.fbcdn.net×1
Social
Registration
- Registrar
- OVH
- Created
- 2018-06-19
- Expires
- 2026-06-19 30 days left
- Updated
- 2025-07-31
- Name servers
-
- dns105.ovh.net
- ns105.ovh.net
DNS records live
- NS
-
- dns105.ovh.net
- ns105.ovh.net
- MX
-
- 1 mx1.mail.ovh.net
- 100 mx3.mail.ovh.net
- 5 mx2.mail.ovh.net
- TXT
-
1|www.lesbonsrestes.frbrevo-code:6b15460f118b1a41f1f782963107bee8google-site-verification=OUFjJDChkong65T4Em25D6tIQTvNhRVX2D7404E-Abo
Email authentication partial
- SPF
-
v=spf1 include:mx.ovh.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.compolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- permissions-policy
geolocation=(), midi=(), sync-xhr=(self), accelerometer=(), gyroscope=(), magnetometer=(), camera=(), fullscreen=*- x-content-type-options
nosniff- content-security-policy
default-src lesbonsrestes.fr *.lesbonsrestes.fr; script-src 'self' 'unsafe-eval' 'unsafe-inline' challenges.cloudflare.com; script-src-elem 'self' 'unsafe-inline' unpkg.com beacon-v2.helpscout.net sdk.zenchef.com sibforms.com lesbonsrestes.fr *.lesbonsrestes.fr *.facebook.net *.looks-awesome.com *.cloudflare.com *.googleapis.com *.google.com *.jsdelivr.net *.bootstrapcdn.com platform.twitter.com *.youtube.com *.gstatic.com; connect-src 'self' *.sibforms.com *.flowflowapp.com *.googleapis.com *.digitaloceanspaces.com yoast.com; img-src 'self' *.advancedcustomfields.com graph.facebook.com *.googleapis.com *.ytimg.com *.wpforms.com *.google.com *.gstatic.com *.fbcdn.net *.startertemplatecloud.com *.ggpht.com gpsites.co generatepress.com *.w.org *.wp.com secure.gravatar.com *.cloudfront.net ps.w.org wpmudev.com data: blob:; style-src 'self' 'unsafe-inline'; base-uri 'self'; form-action 'self' *.smashballoon.com *.wponlinesupport.com; font-src 'self' maxcdn.bootstrapcdn.com *.gstatic.com *.- strict-transport-security
max-age=31536000; includeSubDomains