mymaxcess.eu
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
Third-party hosts loaded (1)
- consent.cookiefirst.com×1
Social
Contact
DNS records live
- NS
-
- ns17.domaincontrol.com
- ns18.domaincontrol.com
Email authentication no MX
- SPF
- not published
- DMARC
-
v=DMARC1; p=reject; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 33 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com www.paypalobjects.com *.googleapis.com data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.konekti.xyz *.mymaxcess.eu 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.konekti.xyz *.mymaxcess.eu data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.