vinoseleccion.nl
HTML metadata
Technology
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
- Google Fonts
Third-party hosts loaded (6)
- use.typekit.net×4
- fonts.googleapis.com×2
- cdn.segmentaim.com×1
- eu1-config.doofinder.com×1
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Contact
- Phone
- Address
- test, 03500
Registration
- Registrar
- EuroDNS S.A.
- Created
- 2003-02-27
- Updated
- 2023-11-02
- Name servers
-
- ns2-c.entorno.cat
- ns1-b.entorno.es
- ns1-a.entorno.com
- ns2-d.entorno.info
DNS records live
- NS
-
- ns1-a.entorno.com
- ns1-b.entorno.es
- ns2-c.entorno.cat
- ns2-d.entorno.info
- MX
-
- 10 mx1-eu1.ppe-hosted.com
- 10 mx2-eu1.ppe-hosted.com
- TXT
-
ppe-b42398b95b4fbedf2d4f7bafd4f77828d31773a7
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com a:dispatch-eu.ppe-hosted.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 304 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
font-src *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'unsafe-inline' data: maxcdn.bootstrapcdn.com instantcredit.net test.instantcredit.net *.gstatic.com 'self' data: *.vinoseleccion.com *.m2.vinoseleccion.com *.vinoseleccion.nl *.m2.vinoseleccion.nl *.vinoseleccion.fr *.vinoseleccion.de *.vinoseleccion.co.uk *.typekit.net *.cookiebot.com *.googletagmanager.com *.google.com *.analytics.google.com *.google.es *.google-analytics.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paycomet.com api.paycomet.com *.senderglobal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardi