ores.be
HTML metadata
Technology
- CMS
- Nuxt
- JS framework
- Nuxt
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- consent.cookiebot.com×1
- fonts.googleapis.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- dns20.ovh.net
- ns20.ovh.net
- MX
-
- 1 ores-be.mail.protection.outlook.com
- TXT
-
Show 17 TXT records
jm4acbjmjmcncugm3kqem488ca8h4t45lmeav7i7t8sgi525v6qcb4bn0oclkjl22kiq77rk76qdj3j0tradlnfklnmd2mrqrjlf5kkqbw=s1Da/C5rv6nCRkQp67txQPJdaBkQM9wrElDhhvjrtNF/mgribduae9m16anfmr9desk65u2hleckt012nb5pa6n1tpqvvo2h1obgrg2kvb04inf374qj6j6aubqs62jj6gi4r495naklr884kqghpregl7ur9f8r11ueueaeu2h82gautodesk-domain-verification=YPv6oCNDtx8JRbmSd3IPd5rlcrc8la5oqthj8rtqo732385P3JT1ARGPVO93KEKF1U6U2DB2b42n0md12mfnyv2hrqt0c4gx22pjf2gz226ka3lhgvnd4pkrcicvh8fjju5caqgp1oglctbavj9lmucll1621lnd4sqpupk2vhob6rc4ge1pb8
- Verified for
-
- Airtable
- Apple
- GlobalSign
- Mailgun
- Microsoft 365
- Miro
Email authentication partial
- SPF
-
v=spf1 include:_spf.ores.be include:eu.rp.oracleemaildelivery.com include:spf.mailjet.com include:spf.protection.outlook.com include:_gtw.engie.com include:mail.webropolsurveys.com include:sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:gca7zgk8@ag.eu.dmarcadvisor.com;policy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDALI4Lp9rJP/hSp8ncdObQYuDleSbEqQD7TaotTuWOZe6bW+n73xjbl5wNWzkkl2LFDj/0cd1rwD2+GmKqaO… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx5zJUWQsUsdNN1CvNx/ozfp+UX1j44LYfg01T0AVtzEBD3TgDMmskj/8sB/vki+2RPGV8KWcY/3Wxn… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvqSPvyOTWBSZuElU++Z7fBjLAWWM2KbYZlYamO8gXsjQpJDf+ApmFNGjUzoMO/7qV+y+/8fGm4XhBrZEc3… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCj6aoUtjfedwCx0d/ElEc2AElieJ+I8Zjn6RJdyv8Vmha09oWZ6lt7jvmCqupaUPazXN/jz5If5tjU0Hby17Pyw7…
selectors probed - selector1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 83 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
autoplay=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; script-src 'self' 'unsafe-inline' www.googletagmanager.com www.google-analytics.com ssl.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net www.google.com https://*.hotjar.com buttons-config.sharethis.com platform-cdn.sharethis.com maps.googleapis.com apps.mypurecloud.de *.cookiebot.com openfed.github.io connect.facebook.net https://*.arcgis.com; script-src-elem 'self' data: 'unsafe-inline' www.googletagmanager.com www.google-analytics.com ssl.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net www.google.com https://*.hotjar.com www.youtube.com platform-api.sharethis.com buttons-config.sharethis.com maps.googleapis.com apps.mypurecloud.de consent.cookiebot.com consentcdn.cookiebot.com connect.facebook.net https://*.arcgis.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com https://*.hotjar.com https://*.mypurecloud.de https://*.euc1.pure.cloud https://*.ar- strict-transport-security
max-age=31536000; includeSubDomains