nicolas.com
HTML metadata
Technology
- Server
- *
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (4)
- cdn.cookielaw.org×1
- maps.googleapis.com×1
- www.googleoptimize.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- IP Twins SAS
- Created
- 1995-08-31
- Expires
- 2026-08-30 102 days left
- Updated
- 2025-11-24
- Name servers
-
- ns1.iptwins.net
- ns2.iptwins.net
- ns3.iptwins.com
- ns4.iptwins.com
DNS records live
- NS
-
- ns1.iptwins.net
- ns2.iptwins.net
- ns3.iptwins.com
- ns4.iptwins.com
- MX
-
- 20 esa1.hc506-2.c3s2.iphmx.com
- 30 esa2.hc506-2.c3s2.iphmx.com
- TXT
-
Show 5 TXT records
facebook-domain-verification=o8017nzni44t22o170npe9f6kfpwzegoogle-site-verification=-B_KTvxBGR5Bo9o9RdAP_mhB7k-WkZDwS21ChYELK8YZOOM_verify_pHx5Fsn5SteBRXIVwgvPP3google-site-verification=-LuHU9Mu5SagQWZxiJj11Gl74Z52Ev12qlxM_W9Njg4globalsign-domain-verification=Zqc0e8O3aSdsI1ju8fOZ3e9MOjgJmvkbWsXAzqFnZN
Email authentication partial
- SPF
-
v=spf1 mx ip4:194.150.58.251 include:_spf.orange-business.fr include:spf.mandrillapp.com include:spf.odiso.net include:spf.smtp.icodia.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;rua=mailto:dmarc@nicolas.com;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
GlobalSign RSA OV SSL CA 2018
Expires in 154 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-eval' 'unsafe-inline' https://ct.pinterest.com https://tr.snapchat.com https://td.doubleclick.net/ https://app.goodays.co/ *.nicolas.com https://www.google.com *.facil-iti.app; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ct.pinterest.com https://tr.snapchat.com https://sc-static.net https://events.sk.ht https://rs.clic2buy.com https://s.pinimg.com https://bat.bing.com https://maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net https://code.jquery.com https://www.googleoptimize.com https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://maps.googleapis.com https://cdn.cookielaw.org https://cdn.goodays.co *.nicolas.com www.google.com https://pixels.omnitagjs.com *.facil-iti.app; img-src 'self' https://bat.bing.com https://insight.adsrvr.org https://tr.snapchat.com https://adservice.google.com https://ad.doubleclick.net https://stats.g.doubleclick.net https://www.googletagmanager.com https://license.hybris.com h- strict-transport-security
max-age=31536000; includeSubDomains; preload