travelcar.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- jQuery
- 3.3.1 known XSS (<3.5)
- Cookie consent
-
- Usercentrics
- Fonts
-
- Font Awesome
- Google Fonts
Third-party hosts loaded (7)
- cdn.jsdelivr.net×2
- cdnjs.cloudflare.com×2
- app.usercentrics.eu×1
- code.jquery.com×1
- fonts.googleapis.com×1
- stackpath.bootstrapcdn.com×1
- use.fontawesome.com×1
Social
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 1999-02-22
- Expires
- 2027-02-22 266 days left
- Updated
- 2026-05-15
- Name servers
-
- ns-1187.awsdns-20.org
- ns-1706.awsdns-21.co.uk
- ns-193.awsdns-24.com
- ns-881.awsdns-46.net
DNS records live
- NS
-
- ns-1187.awsdns-20.org
- ns-1706.awsdns-21.co.uk
- ns-193.awsdns-24.com
- ns-881.awsdns-46.net
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
abuseipdb-verification=F1ZKpy4m
- Verified for
-
- 1Password
- Apple
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:ofsys.com ip4:185.61.184.107 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:postmaster@travelcar.compolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9c/3/OSoiIDfG/CDEX723lVL4aOrwWC5pz6JQhDJmnpko6RXSe8FWAEj7weWeiZyW8VvNuwbVHXlFS+5Sth…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 128 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- content-security-policy-report-only
default-src 'self' *; media-src 'self' * data: ; font-src 'self' * data: ; img-src 'self' data: blob: *; script-src * 'unsafe-inline' 'unsafe-eval' data: *; style-src 'self' 'unsafe-inline' *; worker-src 'self' * blob: ; report-uri /api/csp-violation
Links to (6)
- youtube.com×1
- linkedin.com×1
- google.com×1
- free2move.com×1
- facebook.com×1
- apple.com×1
Linked from (14)
- eskytravel.dk×1
- esky.at×1
- eskytravel.it×1
- eskytravel.ch×1
- esky.com×1
- eskytravel.no×1
- esky.fi×1
- esky.se×1
- esky.fr×1
- esky.eu×1
- esky.pt×1
- esky.nl×1
- esky.ie×1
- eskytravel.be×1