mesoestetic.es
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby 6.6.7.2
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (30)
- www.mesoestetic-me.com×6
- www.mesoestetic.com×3
- cdn.cookielaw.org×2
- sherpa.mesoestetic.com×2
- www.mesoestetic.ch×2
- www.mesoestetic.com.au×2
- www.mesoestetic.com.kw×2
- www.mesoestetic.hk×2
- cdn.doofinder.com×1
- chimpstatic.com×1
- eu1-config.doofinder.com×1
- eu1-search.doofinder.com×1
- static.cloudflareinsights.com×1
- www.dwin1.com×1
- www.googletagmanager.com×1
- www.mesoestetic.be×1
- www.mesoestetic.cl×1
- www.mesoestetic.cn×1
- www.mesoestetic.co×1
- www.mesoestetic.co.uk×1
- www.mesoestetic.co.za×1
- www.mesoestetic.com.br×1
- www.mesoestetic.com.ru×1
- www.mesoestetic.com.tr×1
- www.mesoestetic.cr×1
- www.mesoestetic.de×1
- www.mesoestetic.fr×1
- www.mesoestetic.in×1
- www.mesoestetic.it×1
- www.mesoestetic.mx×1
Social
Contact
- Address
- Carrer de la Tecnologia, 25, 08840, Viladecans, Barcelona, ES
DNS records live
- NS
-
- colin.ns.cloudflare.com
- raegan.ns.cloudflare.com
- MX
-
- 0 mesoestetic-es.mail.protection.outlook.com
- TXT
-
CccNs300ZTxZIf7vQSBcu+wQwzKb6DJxZ8ZVj8+0TCUjLoX7Z9euW+Xb7Z0x2IgtMJ+dKy/APdHlht4Rn/NInA==
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a ip4:35.195.103.255 a:et03ww02.okitup.net include:spf.protection.outlook.com include:spf.mandrillapp.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:27c27990d95149d9a75d8b3ac6cbb17b@dmarc-reports.cloudflare.net;policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
WE1
Expires in 76 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' blob: 'unsafe-inline' 'unsafe-eval' https: assets.adobedtm.com *.adobe.com *.google.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.doubleclick.net *.facebook.com *.facebook.net *.paypal.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.amazon.com *.stripe.com *.stripecdn.com *.stripe.network *.zenaps.com *.awin1.com *.doofinder.com *.cookielaw.org *.onetrust.com *.hotjar.com *.hotjar.io *.bing.com *.clarity.ms *.newrelic.com *.nr-data.net form-assets.mailchimp.com chimpstatic.com *.list-manage.com *.pagantis.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com sherpa.mesoestetic.com *.link.com *.moatads.com *.cloudflare.com edge.fullstory.com static.zdassets.com ekr.zdassets.com mesoestetic.zendesk.com g990421675.co g792337340.co g990421676.co g792337342.co g9508048080.co g10300385420.co g10696554090.co g10498469755.co geotargetly-api-2.com- strict-transport-security
max-age=31536000; includeSubDomains; preload