thegood.fr
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- fonts.googleapis.com×2
- js.stripe.com×2
- ced.sascdn.com×1
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- IONOS SE
- Created
- 2020-06-11
- Expires
- 2026-06-11 20 days left
- Updated
- 2025-07-31
- Name servers
-
- ns1041.ui-dns.biz
- ns1047.ui-dns.com
- ns1048.ui-dns.org
- ns1073.ui-dns.de
DNS records live
- NS
-
- ns1041.ui-dns.biz
- ns1047.ui-dns.com
- ns1048.ui-dns.org
- ns1073.ui-dns.de
- MX
-
- 0 thegood-fr.mail.protection.outlook.com
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:mailers.novius.net -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; fo=0; adkim=r; aspf=r; pct=100policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlcIq6JBYz+s2v+nMJCXtNvZPBlSboWYJ2B99FbdxWYI2JtHeVnC35DQX6VkCzjOWgfl0cT3+eiVhAP…
selectors probed - selector1:
Certificate (current)
R13
Expires in 72 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.google-analytics.com https://www.googletagmanager.com https://tagmanager.google.com https://www.google.com https://ajax.googleapis.com https://www.gstatic.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.youtube.com https://connect.facebook.net https://assets.poool.fr https://ced.sascdn.com https://code.jquery.com https://*.stripe.com https://*.stripe.network https://www.smartadserver.com https://cdn.id5-sync.com https://ced-ns.sascdn.com https://platform.twitter.com https://q.stripe.com https://static.axept.io https://t.novius.net https://cdn.novius.net; object-src 'self'; worker-src blob:- strict-transport-security
max-age=31536000; includeSubDomains; preload
thegood.fr