oikos.com
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- smartmedia.digital4danone.com×89
- static-p72053-e643882.adobeaemcloud.com×2
- apps.bazaarvoice.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 1995-08-19
- Expires
- 2026-08-18 90 days left
- Updated
- 2025-06-30
- Name servers
-
- dns1.cscdns.net
- dns2.cscdns.net
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 10 custmx.cscdns.net
- TXT
-
Show 4 TXT records
google-site-verification=jXU-af4D54ws4HsO42bjKpAnfX-VLewgr3sddslwQKIgoogle-site-verification=yNXKJ3ZgnE5sW8a57eraYoK5n1EE8m2QJsyASdURkG0google-site-verification=55JK23w5AM4cE5Tf1hvUl8UMgLH0yaFvPkMBO-zBE00google-site-verification=VckQfPoHcql51pvnW-5YjswUcD5016vYZH1tblOozrg
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 15 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(self "https://heurekatech.com"), microphone=(self "https://heurekatech.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self' ; style-src 'self' 'unsafe-inline' *.bazaarvoice.com/ *.amazonaws.com/ *.audioeye.com/ *.activia.us.com/ *.freshchat.com/ *.my.salesforce-sites.com *.tiktok.com *.typekit.net/ *.adobeaemcloud.com/ *.force.com/ *.salesforce.com/ *.youtube.com youtube.com https://app.chargebee.com/ *.adyen.com/ *.chargebee.com/ *.static.criteo.net/ *.tagcommander.com/ *.google.com/ *.google-analytics.com/ *.analytics.google.com/ *.googlesyndication.com/ *.doubleclick.net/ *.gstatic.com/ *.googleapis.com/ *.googletagmanager.com/ *.trustcommander.net/ *.aemcs.digital4danone.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bazaarvoice.com/ *.audioeye.com/ *.activia.us.com/ *.amazonaws.com/ *.freshchat.com/ https://js-agent.newrelic.com/ *.my.salesforce-sites.com *.tiktok.com *.monitor.azure.com/ *.youtube.com/ *.channelsight.com/ *.typekit.net/ *.adobeaemcloud.com/ *.salesforceliveagent.com/ *.force.com/ *.salesforce.com/ https://app.chargebee.com/ *.paypal.com/ *.googlesyn- strict-transport-security
max-age=63072000; includeSubDomains; preload