montres-de-luxe.com
HTML metadata
Technology
- CDN
- Cloudflare
- jQuery
- 1.8.3 known XSS (<3.5)
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (2)
- cdn.consentmanager.net×1
- static.cloudflareinsights.com×1
Registration
- Registrar
- Gandi SAS
- Created
- 2005-11-17
- Expires
- 2032-11-17 2357 days left
- Updated
- 2025-11-20
- Name servers
-
- alexis.ns.cloudflare.com
- shubhi.ns.cloudflare.com
DNS records live
- NS
-
- alexis.ns.cloudflare.com
- shubhi.ns.cloudflare.com
- MX
-
- 10 smtp01.wmaker.net
- 20 smtp02.wmaker.net
Email authentication partial
- SPF
-
v=spf1 ip4:94.23.134.224/27 ip4:213.251.158.192/27 ip4:154.56.81.64/26 ip4:130.117.9.64/26 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; sp=none; aspf=r; adkim=r;policy: none (monitoring only) · sp=none - DKIM
-
- default:
v=DKIM1; t=y; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxYV/F+XqEuEQjVv7dFRaIhR5+t/LMVpoQF+Ql7dEKFU4cZ+31XeUved7CmsrFadE9lXQIx6ntj8fxT…
selectors probed - default:
Certificate (current)
WE1
Expires in 69 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://cdn.ampproject.org https://cdn.consentmanager.net https://c.delivery.consentmanager.net; connect-src 'self' https://www.montres-de-luxe.com https://www.google-analytics.com https://region1.google-analytics.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://cloudflareinsights.com https://c.delivery.consentmanager.net https://delivery.consentmanager.net; img-src 'self' data: https:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://safeframe.googlesyndication.com https://www.google.com- strict-transport-security
max-age=31536000;