shiseido.es
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- fasterize
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (17)
- cdn.jsdelivr.net×3
- 100014054.collect.igodigital.com×2
- cdn.cquotient.com×2
- try.abtasty.com×2
- apps.bazaarvoice.com×1
- cdn.c360a.salesforce.com×1
- cdn.cookielaw.org×1
- dcinfos-cache.abtasty.com×1
- e.cquotient.com×1
- lcx-embed.bambuser.com×1
- static.cloudflareinsights.com×1
- www.googletagmanager.com×1
- www.paypal.com×1
- www.shiseido.co.uk×1
- www.shiseido.com×1
- www.shiseido.me×1
- www.youtube.com×1
Social
Contact
- Phone
- Address
- RUE DE VILLIERS92200
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 10 mxa-0015f201.gslb.pphosted.com
- 10 mxb-0015f201.gslb.pphosted.com
- TXT
-
Show 5 TXT records
k2u7vm8skb73r1nteb9ekup9t8uq165i9ub6kp9tb4c91218nanrvieci564fj45vb9mc8rmgbbvel976129df-380e-4c46-95a3-d88f1fe92429WyBoIZQhoHvN3ilCiVqOSknh/gyiKYI2l9wKwcMEaYctQPfXn2z0ansoGrKqw5e5OGfMRZgW6c6zHv5U/abxcA==
- Verified for
-
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx ip4:27.126.148.96/27 ip4:27.126.147.96/27 ip4:27.126.146.96/27 ip4:2 05.166.177.0/24 ip4:204.75.142.0/24 ip4:203.55.21.0/24 ip4:103.28.42.0/24 include:createsend.com include:createsend1.com include:createsend20.com include:cmail1.com include:cmail20.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 73 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self)- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' * tag.wknd.ai assets.bounceexchange.com api.bounceexchange.com dev.bounceexchange.com dash-staging.bounceexchange.com https://cdn.gbqofs.com/ https://connect.facebook.net https://www.google-analytics.com https://www.googletagmanager.com https://www.youtube.com; style-src * 'self' 'unsafe-inline' assets.bounceexchange.com; img-src * 'self' blob: data: assets.bounceexchange.com events.bouncex.net; font-src * 'self' data: assets.bounceexchange.com; child-src assets.bounceexchange.com; worker-src * 'self' blob: assets.bounceexchange.com; frame-src * 'self' assets.bounceexchange.com dash-staging.bounceexchange.com; form-action * 'self' api.bounceexchange.com dev.bounceexchange.com; connect-src * 'self' events.bouncex.net coupons.bounceexchange.com *.cdnwidget.com *.cdnbasket.net;- strict-transport-security
max-age=2592000; includeSubDomains