myhiscox.es
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- www.google.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns1-01.azure-dns.com
- ns2-01.azure-dns.net
- ns3-01.azure-dns.org
- ns4-01.azure-dns.info
- MX
-
- 10 relay1.netnames.net
- 20 relay2.netnames.net
- TXT
-
Show 8 TXT records
08sgwbl591vvmbsp9dps2tyvwdfgg93dls00w0305n5814gx8g6mb28pz9j5tkhp_globalsign-domain-verification=e_ZCz7gYZRM9A0OGM6RI-bkyG8tdcFcGb-otNvLaeifbrt1y8nb56ylw44w8b106zcfw8tn92349kvqhx6l4n4k4mp45xsdnt5xwc47fq1_9he6cdkptthol3ocuewqsjdtmrk87fe_6q83hf666a3om7su9d0b4ne97wrkhj9_globalsign-domain-verification=58O9w_QzCpPUl0WyVrtb_tNgvgLm-LXtdYDMq-t0s2
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 210 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), payment=()- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; script-src 'self' 'unsafe-inline' *.myhiscox.es *.zscloud.net *.google.com *.googleapis.com *.googletagmanager.com cdn.cookielaw.org cdn.ampproject.org *.gstatic.com ; frame-src 'self' *.myhiscox.es *.zscloud.net *.google.com *.googleapis.com *.youtube.com *.googletagmanager.com *.gstatic.com ; object-src 'none'; media-src 'none';- strict-transport-security
max-age=31536000; includeSubDomains; preload