villagelaplage.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- Nuxt
- JS framework
- Nuxt, Vue
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- medias.yellohvillage.fr×20
- img.yellohvillage.fr×6
- fonts.googleapis.com×1
- img.youtube.com×1
Social
Contact
- Phone
- Address
- 241 Hent Maner Ar Ster, 29760, Penmarc'h, Bretagne, France
Registration
- Registrar
- OVH sas
- Created
- 2005-12-08
- Expires
- 2026-12-08 190 days left
- Updated
- 2025-12-09
- Name servers
-
- dns200.anycast.me
- ns200.anycast.me
DNS records live
- NS
-
- dns200.anycast.me
- ns200.anycast.me
- MX
-
- 1 mx1.ovh.net
- 100 mxb.ovh.net
- 5 mx2.ovh.net
- TXT
-
4|https://www.villagelaplage.com
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 include:mx.ovh.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 27 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), geolocation=(self), fullscreen=(), autoplay=(), camera=(), display-capture=(self)- x-content-type-options
nosniff- content-security-policy
frame-src 'self' blob: https://yellohvillage.demdex.net https://*.youtube-nocookie.com https://*.google.com https://*.facebook.com https://*.fls.doubleclick.net https://*.iadvize.com https://*.web-visite.com https://atlanticdigital.fr https://*.zenchef.com https://*.apidae-tourisme.com https://*.yellohvillage.fr https://*.adoberesources.net https://*.adobedc.net https://www.googletagmanager.com;script-src-elem 'self' 'unsafe-inline' https://assets.adobedtm.com https://js-agent.newrelic.com https://*.gstatic.com https://*.google.com https://*.facebook.net https://*.bing.com https://*.google-analytics.com https://cdn.mouseflow.com https://sdk.privacy-center.org https://*.googletagmanager.com https://yellohvillage.script.admo.tv https://*.adoberesources.net https://*.adobedc.net blob: https://*.iadvize.com https://elfsightcdn.com https://*.elfsightcdn.com https://*.elfsight.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.privacy-center.org https://*.adoberesources.net https:- strict-transport-security
max-age=31536000; includeSubDomains