welhometravel.fr

.fr crawl

First seen 2026-05-04 · Last seen 2026-05-11 · ok HTTP/1.1 200 3589 ms crawled 2026-05-11

US · 76.223.14.214 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Welhome Travel - Locations de vacances haut de gamme en France et Tahiti
Description
Découvrez des villas et appartements d'exception en Provence, Corse, Côte Basque et la Polynésie française avec Welhome Travel. Meilleur prix garanti pour un séjour unique.
Language
fr
Canonical
https://www.welhometravel.fr/

Technology

Fonts
  • Google Fonts
Third-party hosts loaded (7)
  • d6644ef6a12fcfb82f3f-5d6761b1e7eae8e264ad220502fbb6f0.ssl.cf5.rackcdn.com×14
  • cdn.bookingsync.io×2
  • fonts.googleapis.com×2
  • res-3.cloudinary.com×2
  • res-5.cloudinary.com×2
  • fonts.gstatic.com×1
  • res-2.cloudinary.com×1

Social

Contact

Email

Registration

Registrar
OVH
Created
2024-03-14
Expires
2027-03-14 297 days left
Updated
2026-04-30
Name servers
  • dns12.ovh.net
  • ns12.ovh.net

DNS records live

NS
  • dns12.ovh.net
  • ns12.ovh.net
MX
  • 1 mx1.mail.ovh.net
  • 100 mx3.mail.ovh.net
  • 5 mx2.mail.ovh.net
Verified for
  • Google

Email authentication weak

SPF
v=spf1 include:mx.ovh.com -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-05-06 to 2026-08-04
Expires in 76 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.welhometravel.fr/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing content type protection
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
sameorigin
permissions-policy
camera=(), geolocation=()
content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval'; connect-src *; font-src * data:; frame-ancestors 'self' www.bookingsync.com *.bookingsync.com *.smily.com; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline' blob:; worker-src * blob:
strict-transport-security
max-age=31536000; includeSubDomains

Links to (6)

Linked from (1)