lotana.be
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- dashboard.trustprofile.com×2
- cdn.brevo.com×1
- cdn.cookie-script.com×1
- use.typekit.net×1
- www.googletagmanager.com×1
Contact
- Phone
DNS records live
- NS
-
- ns1.hosted-power.com
- ns2.hosted-power.com
- ns3.hosted-power.com
- MX
-
- 0 lotana-be.mail.protection.outlook.com
- TXT
-
mandrill_verify.gGjjWqndpLxKtTd7D_HHTA
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:84.22.101.13 ip4:94.237.108.77 ip6:2a04:3544:1000:1510:3cc8:64ff:fefa:39f6 ip4:94.237.125.79 ip6:2a04:3544:1000:1510:3cc8:64ff:fefa:3bb3 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400;rua=mailto:server@lotana.be;ruf=mailto:server@lotana.bepolicy: reject (enforced) · sp=none - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmbdnK0fFHH/VykTSWs9b8yOYbWlIF5jRwaQtvKdfH7go+5D11h1c5srunv51XiqER6sHra4uqk0iiA… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzYatpPPpB25xnfy/XqJWWixo5VqmiBD7CIGUgfGRh9FuRVtcqEfiEsWOrgPgZ3WtjA/83NvPPoZ6qb…
selectors probed - default:
Certificate (current)
E8
Expires in 73 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing Content Security Policy
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- strict-transport-security
max-age=31536000; preload- content-security-policy-report-only
font-src i.icomoon.io fonts.gstatic.com *.typekit.net *.gstatic.com 'self' data: https://dashboard.trustprofile.comfonts/webandbrand.woff data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.becom.digital *.facebook.com *.glimps.group *.google.com *.sibforms.com *.trustprofile.com *.youtube-nocookie.com becom.digital www.googletagmanager.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net https://dashboard.trustprofile.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.doubleclick.net *.facebook.com *.