winiary.pl
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (20)
- cdnjs.cloudflare.com×3
- www.maggi.lt×3
- www.maggi.cm×2
- www.maggiarabia.com×2
- cdn.jsdelivr.net×1
- tintup.com×1
- www.googletagmanager.com×1
- www.maggi.at×1
- www.maggi.ci×1
- www.maggi.co.uk×1
- www.maggi.co.za×1
- www.maggi.com.gh×1
- www.maggi.com.vn×1
- www.maggi.hu×1
- www.maggi.id×1
- www.maggi.ng×1
- www.maggi.ph×1
- www.maggi.sn×1
- www.maggicooking.gr×1
- www.maggitalia.it×1
Social
DNS records live
- NS
-
- amsdns1.nestle.com
- aoadns1.nestle.com
- ctrdns1.nestle.com
- eurdns1.nestle.com
- MX
-
- 10 winiary-pl.mail.protection.outlook.com
- TXT
-
v=msv1 t=BABB199A-B233-4AD6-8B23-1E93E2B6246C
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.emailpolicy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD30opOg/If/lb8NhrJlMHAioRS2FIS50EMIupyLC878jjjhIMwD40LW0V/sqZp5lTjsyrGKQRBo6XNbELBz2… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5PkY6ZDJBp+uz3mCjQnhRsUBfQ3e9GLAp6QeT0c4YaOL9puRyISDpD4e4ceh14pAJzAkDGtXZd0kEVNV0u9… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3X3bHO2ffxgcXLcGRtm81IxLxIMZ7nYycXSP5hLyfvo06N/M3MQpgvC+mf70b5aK8iLPMdD5GgVtG3yI3S… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCvYQzOWdYuB59B/zW1RHy41TIgngXdQqh6K/0/u4xdpEw6LGTAvBiS9crgKsOObrG/IzboZXYVHPlEAEBAt7bRTy…
selectors probed - selector1:
Certificate (current)
Certainly Intermediate R1
Expires in 12 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=self, geolocation=self- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.my-shopify.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com recaptcha.net:* googleads.g.doubleclick.net *.googletagmanager.com c.evidon.com youtube-nocookie.com connect.facebook.net *.google-analytics.com d2oh4tlt9mrke9.cloudfront.net *.sessioncam.com *.google.com s2.go-mpulse.net js-agent.newrelic.com *.cdn.cookielaw.org *.cookie-cdn.cookiepro.com *.onetrust.com cdn.cookielaw.org d6tizftlrpuof.cloudfront.net *.usabilla.com *.gbqofs.io *.gbqofs.com d22xmn10vbouk4.cloudfront.net *.youtube.com github.com cdnjs.cloudflare.com p.teads.tv *.tintup.com objects.githubusercontent.com cdns.eu1.gigya.com cdn.hypemarks.com pxl.jivox.com *.nestle.com *.adimo.co googleoptimize.com *.gigya.com *.d6tizftlrpuof.cloudfront.net https://tintup.com cdn.jsdelivr.net/npm/@popperjs/core@2.11.5/dist/umd/popper.min.js files.qualifio.com/kit/qualp.2.min.js scripts.qualifioapp.com/kit/plugins/iframe.js *.unpkg.com https://unpkg.com https://cdn.az.ciam.nestle.com *.nestle.c- strict-transport-security
max-age=31622400; includeSubDomains; preload