win-waste.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Stack
- ASP.NET
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- cdnjs.cloudflare.com×3
- citycarting3456.my.site.com×1
- dl.episerver.net×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 2020-11-17
- Expires
- 2026-11-17 180 days left
- Updated
- 2025-10-18
- Name servers
-
- lisa.ns.cloudflare.com
- pablo.ns.cloudflare.com
DNS records live
- NS
-
- lisa.ns.cloudflare.com
- pablo.ns.cloudflare.com
- MX
-
- 0 winwaste-com0i.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
438t6qddidds61g63gp3majbjeif0avntg4j5o6a17gnlimlle45jamf-site-verification=ZtAnsipamOOqvLSBEpiXXgkfaqh388siuv7e664rh6jpubfiknlbft6m6sgobtdi0b1j2tlbggsgrp8pfluff1nghckvr2lcs3pi
- Verified for
-
- Apple
- Atlassian
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:_spf.psm.knowbe4.com include:_spf.salesforce.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:d8753006681b4f0f94f5f313f2812113@dmarc-reports.cloudflare.net,mailto:dmarc-notifications@win-waste.com; ruf=mailto:dmarc-notifications@win-waste.com;policy: quarantine - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsOj3ZKpiTe6oeDbY9pz0aRk118zFU4dN4m08e2ym+JN94+cGPSN6yzJFe084KniIaz1VS8C5zSZkfG… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA22lrMy4oht6QZCvBEHsjK3jvQz8xBW19kM1dhIHiGYSdIj/K4vEWfezDumVC9vX1xz44UZo9gM+nc3… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0Uht8CEWls7rn0ocMwrfx/hBS9okd67CGJUiwVzAAlK3nlpQYqoCobP0JtvnjwEPVw4mZ2Zwv53YlgzSqD… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4hGsYyNvEaz9Hy6y7/SwgQboBIy7Dw2vhlL88HgCtPBwRClwizyIPYBRs4XIo0dx4lKsKcUd9uTAiQ5G/N…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 55 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
%0abase-uri 'self';%0a%0ascript-src%0a 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline'%0a *.app.onetrust.com%0a *.onetrust.com%0a *.cookielaw.org%0a *.cloudflare.com%0a *.geolocation.onetrust.com%0a *.doubleclick.net%0a *.facebook.com%0a *.facebook.net%0a *.force.com%0a *.google-analytics.com%0a *.google.com%0a *.googleadservices.com%0a *.vimeo.com%0a *.googleapis.com%0a *.googlesyndication.com%0a *.googletagmanager.com%0a *.gstatic.com%0a *.licdn.com%0a *.msecnd.net%0a *.my.salesforce-sites.com%0a *.my.salesforce.com%0a *.oktacdn.com%0a *.pagespeed-mod.com%0a *.salesforceliveagent.com%0a *.sharethis.com%0a https://buttons-config.sharethis.com/js/61e9998e96a4850019cacc8b.js%0a https://cdn.jsdelivr.net/npm/bootstrap@5.3.0/dist/js/bootstrap.bundle.min.js%0a https://cdnjs.cloudflare.com/ajax/libs/gsap/3.9.1/gsap.min.js%0a https://citycarting3456.my.salesforce-sites.com/liveAgentSetupFlow/*%0a https://citycarting3456.my.salesforce.com/lightning/lightning- strict-transport-security
max-age=31536000