libecohomestores.eu
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Fonts
-
- Font Awesome
Third-party hosts loaded (5)
- libeco.imgix.net×17
- cdn-images.mailchimp.com×1
- chimpstatic.com×1
- fast.fonts.net×1
- use.fontawesome.com×1
Social
DNS records live
- NS
-
- arvind.ns.cloudflare.com
- faye.ns.cloudflare.com
- MX
-
- 0 libecohomestores-eu.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:94.237.110.123 ip4:62.213.218.59 ip4:195.130.132.32/27 ip4:195.130.137.64/27 ip6:2a02:1800:110:4::/64 ip6:2a02:1800:120:4::/64 include:spf.mail.cloudstar.be include:servers.mcsv.net include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantinepolicy: quarantine - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
v=DKIM1;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC4W5hJxBdz/U+L1fVSs+E/41cLsORvoBhDQ/X1k61/JD68WTqrg7stAyR7YHWChU5+cVbGixcvIpQKPPpYvGB9jc…
selectors probed - k2:
Certificate (current)
E8
Expires in 63 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
font-src *.gstatic.com 'self' data: *.doubleclick.net data: https://fonts.gstatic.com/ https://fast.fonts.net/ https://use.fontawesome.com/ 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net https://www.facebook.com/ https://libecohomestores.us6.list-manage.com/ mc.us6.list-manage.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com https://www.google.com/ *.doubleclick.net js.mollie.com *.multisafepay.com https://pay.google.com https://www.youtube.com https://play- strict-transport-security
max-age=31536000; includeSubDomains; preload;