nestlegoodnes.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-08 · ok HTTP/1.1 200 527 ms crawled 2026-05-08

US · 151.101.194.133 · AS54113 Fastly, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Homepage - Guest | Nestlé Goodnes
Description
Welcome to Goodnes! Step into a world of tasty recipes and healthy habits for the whole family. And if you need a hand, just ask your Buddies!
Language
en
Canonical
https://www.nestlegoodnes.com/
Translations
  • en

Open Graph

url
https://www.nestlegoodnes.com/home
title
Homepage - Guest | Nestlé Goodnes
image:url
https://www.nestlegoodnes.com/themes/custom/gfy/images/nestle-goodnes-og.png
site name
Nestlé Goodnes

Technology

Server
nginx
CMS
Drupal
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • cdn.jsdelivr.net×4
  • www.googletagmanager.com×1

Registration

Registrar
Nom-iq Ltd. dba COM LAUDE
Created
2024-03-26
Expires
2027-03-26 310 days left
Updated
2026-02-24
Name servers
  • amsdns1.nestle.com
  • aoadns1.nestle.com
  • ctrdns1.nestle.com
  • eurdns1.nestle.com

DNS records live

NS
  • amsdns1.nestle.com
  • aoadns1.nestle.com
  • ctrdns1.nestle.com
  • eurdns1.nestle.com
TXT
  • _xo3cdnh450pgpjoxp94sg3lnobp5y82
  • google-site-verification=LzAnDs3yMeo2b8WWF2AWl5xKP7EfUrc81-AoSnh_YiA
  • _esp1qucs08rv37ybtbkcjwlqoggmeh7

Email authentication no MX

SPF
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

Certainly Intermediate R1
from 2026-05-05 to 2026-06-04
Expires in 15 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.nestlegoodnes.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com code.jquery.com:* static.addtoany.com:* cdn.jsdelivr.net:* googleads.g.doubleclick.net:* connect.facebook.net:* cdnjs.cloudflare.com:* cdn.cookielaw.org:* *.gigya.com:* *.qualtrics.com *.adimo.co:* app.tintup.com:* tintup.com:* www.tintup.com www.google.com www.recaptcha.net www.gstatic.com *.nestlegoodnes.com js-agent.newrelic.com:* assets.pinterest.com:* *.atlassian.net:* apis.google.com:* *.qualifioapp.com; object-src 'none'; frame-src 'self' www.google.com www.recaptcha.net www.gstatic.com recaptcha.google.com static.addtoany.com:* td.doubleclick.net:* www.googletagmanager.com *.gigya.com *.qualtrics.com td.doubleclick.net www.facebook.com app.tintup.com www.tintup.com *.adimo.co assets.pinterest.com *.atlassian.net *.youtube.com *.qualifioapp.com; frame-ancestors 'self' www.google.com www.recaptcha.net www.gstatic.com recaptcha.google.com static.addtoany.com:* td.doubleclick.net:* www.googletagmanager.com *.gi
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)