valrhona-selection.it
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Gatsby
Third-party hosts loaded (3)
- maxcdn.bootstrapcdn.com×1
- stackpath.bootstrapcdn.com×1
- valrhona.my.site.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- a.ns.domainoo.fr
- b.ns.domainoo.fr
- c.ns.domainoo.fr
- d.ns.domainoo.fr
- MX
-
- 10 a.mx.domainoo.fr
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 a mx include:spf.domainoo.fr -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 95 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
style-src-elem 'self' 'unsafe-inline' *.bootstrapcdn.com *.valrhona-collection.com www.gstatic.com *.googleapis.com cdnjs.cloudflare.com/ajax/libs/ion-rangeslider/2.3.1/css/ https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.css https://tag.beyable.com/ https://*.iadvize.com https://*.my.site.com https://*.my.salesforce-scrt.com https://www.googletagmanager.com; report-uri https://coremodelecommercefsp.report-uri.com/r/d/csp/reportOnly; script-src-elem 'self' 'unsafe-inline' cdn.cookielaw.org googleads.g.doubleclick.net js-agent.newrelic.com static.hotjar.com script.hotjar.com www.googletagmanager.com www.google.com cdn.jsdelivr.net https://www.gstatic.com/ www.googleadservices.com *.beyable.com connect.facebook.net az693360.vo.msecnd.net/javascript/by_slider.min.js https://cdnjs.cloudflare.com/ajax/libs/jquery.lazy/1.7.10/jquery.lazy.min.js *.googlesyndication.com *.cloudfront.net/bynder-embed/latest/bynder-embed.js https://*.iadvize.com https://gateway.zscloud.net h- strict-transport-security
max-age=31536000; includeSubDomains