nexion.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Meta Pixel
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (8)
- fonts.googleapis.com×4
- www.googletagmanager.com×3
- player.vimeo.com×2
- connect.facebook.net×1
- fonts.axept.io×1
- gmpg.org×1
- static.axept.io×1
- www.google-analytics.com×1
Social
Contact
- Phone
- Address
- st travel agency since 1995
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 2004-06-29
- Expires
- 2027-06-29 405 days left
- Updated
- 2025-09-29
- Name servers
-
- brit.ns.cloudflare.com
- rene.ns.cloudflare.com
DNS records live
- NS
-
- brit.ns.cloudflare.com
- rene.ns.cloudflare.com
- MX
-
- 10 us-smtp-inbound-1.mimecast.com
- 10 us-smtp-inbound-2.mimecast.com
- TXT
-
Show 8 TXT records
atlassian-domain-verification=bQD6OhkZJxU4VRUYfJhbajXLF88jBw7m9EYu0Kd84Eajw6dkrRIPkXcYhPJyK7szdocusign=b41efc02-7973-44a5-a513-a31452787bd8google-site-verification=8z51yLFy_XqrYplAKDP-CTrg3qbzArhfUJwvIqCNTXYgoogle-site-verification=VE_2QulmZGP1T4IEwsMSQsVk7HfWBPgqS9_VXxcn3nQloom-site-verification=d66ab736b61b4c729b91af079d6d5afdsmartsheet-site-validation=HWQKPcRt5Fp1XMfY55SzA5LnnXbFfNe3tnnv6rs9u2pe51s7rnl44avo25yahoo-verification-key=sDUuncNjzW1v1JocNzu9az/TqoCtjWbFUYGVO5pyWAY=
Email authentication strong
- SPF
-
v=spf1 include:us._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.concurcompleat.com include:mail.zendesk.com ip4:209.143.136.220 ip4:63.240.73.36 ip4:206.19.237.135 ip4:72.249.160.11 ip4:72.249.160.12 ip4:64.17.5.11 ip4:216.52.91.238 ip4:204.10.146.19 ip4:208.85.48.176 include:_spf.salesforce.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:0510be4f2618042@rep.dmarcanalyzer.com; ruf=mailto:0510be4f2618042@for.dmarcanalyzer.com; adkim=s; aspf=s; fo=1;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
DENY- permissions-policy
geolocation=(self), microphone=(self), camera=(self), fullscreen=(self), payment=(self)- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval';- strict-transport-security
max-age=63072000; includeSubDomains