vsl.com
HTML metadata
Technology
- Server
- Nginx
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- fonts.gstatic.com×6
- fonts.googleapis.com×5
- unpkg.com×4
- www.google.com×2
- snap.licdn.com×1
- www.googletagmanager.com×1
- www.gstatic.com×1
Social
Contact
- Address
- Wankdorfallee 5, 3014, Bern, CH
Registration
- Registrar
- Nameshield SAS
- Created
- 1993-08-23
- Expires
- 2026-08-22 94 days left
- Updated
- 2025-08-20
- Name servers
-
- nsa.perf1.fr
- nsb.perf1.com
- nsc.perf1.com
DNS records live
- NS
-
- nsa.perf1.fr
- nsb.perf1.com
- nsc.perf1.com
- MX
-
- 10 secours.bouygues-construction.com
- 5 concentrateur.bouygues-construction.com
- TXT
-
Show 14 TXT records
canva-site-verification=_hjdKDB8ix_PQV-8sNNx3Qbrevo-code:b0658595e7d8b949d8e5204a92979498atlassian-domain-verification=JIPczthvWnHawesYuz61rR9yTu/C6xH1kdIYmj9yfqj/HE5Rj1eHVu6ZsPSi/j1ydocusign=c32a6ba3-443f-48e5-b386-2936cd7901fcnitro-verification-code=LTYzMDIwMjIyNTQ3NjkzODU0MDM=autodesk-domain-verification=RW3175eePKMQflpH6_acgoogle-gws-recovery-domain-verification=68057785teamviewer-sso-verification=6547229b5b8b417084ab3b957a9c67f1docusign=67c91d21-3722-4920-bcac-e6c8edf26c77MS=ms69429968google-site-verification=V084OAFLpqj6UpuQf6aWsTjE4VFW9mlac7ZX32LTzSIsending_domain1088432=e5a84481bd762f9299d91bd8151bf8deea7d536e4c0d1f3cb4faa4f10d31d748W2ql0KC3f2aqpytfiG7vt4nVMlfET0Ht2S2aAW/6bc9MCMFajcB2sD9+G1wQUwW82L76tIK0WLfD7KAQo2Dnnw==sending_domain1003331=0ae6315582bfd9f3b74c0605397f8e4ea937e8c29b73fcf4b1fc7066719f1261
Email authentication strong
- SPF
-
v=spf1 include:spf.mailjet.com a:concentrateur.bouygues-construction.com ip4:193.57.109.0/24 ip4:172.104.157.22 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_reports@bouygues-construction.com; ruf=mailto:dmarc_reports@bouygues-construction.com; sp=reject;policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV E36
Expires in 281 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; frame-ancestors *; form-action 'self'; upgrade-insecure-requests; style-src 'unsafe-inline' https://vsl.com https://cdnjs.cloudflare.com/ https://unpkg.com/ https://fonts.googleapis.com https://cdn.jsdelivr.net/ https://netdna.bootstrapcdn.com/bootstrap/3.1.1/css/bootstrap.min.css https://www.googletagmanager.com; script-src 'unsafe-inline' 'unsafe-eval' 'self' blob: data: https://vsl.com https://api.websitecarbon.com/ https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com/ https://www.youtube.com https://www.youtube-nocookie.com https://cdn.jsdelivr.net/ https://www.googletagmanager.com/ https://api.websitecarbon.com/ https://unpkg.com/ https://cdnjs.cloudflare.com/ https://www.googletagmanager.com/gtag/js https://cdn.jsdelivr.net/ https://snap.licdn.com/; object-src 'none'; base-uri 'self'; worker-src 'self' blob:; frame-src 'self' https://www.youtube-nocookie.com/ https://www.google.co- strict-transport-security
max-age=63072000; includeSubDomains; preload