visitalderney.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (5)
- cloud.typography.com×1
- js.createsend1.com×1
- player.vimeo.com×1
- use.typekit.net×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- Key-Systems GmbH
- Created
- 2004-03-05
- Expires
- 2027-03-05 289 days left
- Updated
- 2026-01-30
- Name servers
-
- dns1.name-s.net
- dns2.name-s.net
- dns3.mtgsy.com
- dns4.mtgsy.com
DNS records live
- NS
-
- dns1.name-s.net
- dns2.name-s.net
- dns3.mtgsy.com
- dns4.mtgsy.com
- MX
-
- 10 mail6.mtgsy.net
Email authentication partial
- SPF
-
v=spf1 include:_spf.createsend.com include:_spf.mtgsy.net ip4:54.194.13.56 mx ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 70 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src https: data: 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com *.googletagmanager.com *.fonts.net *.createsend1.com google.com *.google.com *.googleapis.com gstatic.com *.gstatic.com cdn.3cx.com *.vimeo.com *.bunny.net webreality.co.uk cdn-cookieyes.com f.vimeocdn.com vimeo.com *.juicer.io 'nonce-504c81c14ad449ca8974794a96c5bbda'; style-src 'self' 'unsafe-inline' *.fonts.net *.cloudfront.net *.typekit.net *.googleapis.com fonts.googleapis.com *.bunny.net *.typography.com *.juicer.io *.visitalderney.com; img-src 'self' data: https: *.google-analytics.com google-analytics.com google-analytics.com *.umbraco.org gravatar.com *.gravatar.com gstatic.com *.gstatic.com i1.wp.com cdn-cookieyes.com *.juicer.io; connect-src 'self' *.analytics.google.com analytics.google.com *.doubleclick.net https://*.cookiescan.com https://*.google-analytics.com wss: *.cookieyes.com cdn-cookieyes.com *.vimeo.com vimeo.com *.googlesyndication.com *.juicer.io *.google.com *- strict-transport-security
max-age=31536000