michelin.se
HTML metadata
Technology
- CDN
- Azure Front Door
Third-party hosts loaded (4)
- adzktgbqdq.cloudimg.io×27
- img.youtube.com×2
- 9e9soula8o.kameleoon.eu×1
- halc.iadvize.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- udns1.cscdns.net
- udns2.cscdns.uk
- TXT
-
Show 5 TXT records
194q34gv49bm7c3bnhrdbq3lx4z4k89r_p85n6bmitgoxkfnqagix62s4rxvvyewd61jh2l50m3688jxk9g7hx30rpmlcscvn2nmfckp933x1xxtv9pmsy83xqkp6xyb104hth6kdx4cz59drdwckj8dzsbcq3sg
- Verified for
-
- Meta
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- content-security-policy
default-src *; img-src * blob: data:; style-src 'unsafe-inline' *; script-src 'unsafe-inline' 'unsafe-eval' *; font-src * data:; worker-src 'self' blob: https://via.batch.com; frame-src 'self' *.cxf-public-multisite.prod-we-cxf.michelin.fr *.youtube.com *.google.com *.hcaptcha.com *.qualtrics.com *.googletagmanager.com https://itworks.agency https://mcx0vvrj5ql5kfmyh03-jt9sq6d1.pub.sfmc-content.com https://wiper-blade.webmichelin.com *.iadvize.com- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (11)
Linked from (2)
- dftf.se×1
- euromaster.se×1