options.be
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby 6.6.7
- Stack
- PHP
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- cdn.jsdelivr.net×2
- www.googletagmanager.com×2
- fonts.googleapis.com×1
- www.options-greathire.co.uk×1
- www.options.ch×1
- www.options.es×1
- www.options.fr×1
Social
Contact
DNS records live
- NS
-
- ns1.iptwins.net
- ns2.iptwins.net
- ns3.iptwins.com
- ns4.iptwins.com
- MX
-
- 10 smtp.te-dns.net
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
geolocation=(), microphone=(), camera=()- x-content-type-options
nosniff, nosniff- content-security-policy
font-src *.alothemes.com *.magepow.com https://fonts.gstatic.com 'self' data: *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.googleapis.com *.fontawesome.com *.bootstrapcdn.com *.googletagmanager.com *.iadvize.com *.bing.com *.unpkg.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action *.twitter.com *.facebook.net *.facebook.com *.iadvize.com *.pinterest.net *.pinterest.com *.pinimg.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ https://player.vimeo.com https://www.youtube-nocookie.com *.twitter.com *.google.com *.googletagmanager.com *.addthis.com *.googleapis.com *.facebook.net *.facebook.com *.iadvize.com *.doubleclick.net *.bing.com *.pinterest.net *.pinterest.com *.pinimg.com *.web.app *.wonder-shop.net *.unpkg.com *.canva.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net d- strict-transport-security
max-age=31536000; includeSubDomains