yachtsupport.com
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- medialibrary.damen.com×32
- recaptcha.net×1
- www.googletagmanager.com×1
Social
Contact
- Address
- Koningsweg, 2, 4380 AB, Vlissingen, Zeeland, NL
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 1999-05-08
- Expires
- 2027-05-08 353 days left
- Updated
- 2023-12-27
- Name servers
-
- ns1-38.azure-dns.com
- ns2-38.azure-dns.net
- ns3-38.azure-dns.org
- ns4-38.azure-dns.info
DNS records live
- NS
-
- ns1-38.azure-dns.com
- ns2-38.azure-dns.net
- ns3-38.azure-dns.org
- ns4-38.azure-dns.info
- MX
-
- 10 yachtsupport-com.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
pardot700753=50393d7bf26d6bd7db5bfaef5b5dc57e33f974d2e8c867f0f5313e7969179b49v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.emailgoogle-site-verification=-juvkY4eBhTJ-Ub9G4bvaXpv6DTL9DEo250eAb8PeZ0MS=ms84436316
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 105 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(self), battery=(), camera=(), display-capture=(self), document-domain=("http://localhost:3000" "https://www.amels.com"), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(self), gamepad=(), geolocation=(), gyroscope=(), layout-animations=(self), legacy-image-formats=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), oversized-images=(), payment=(), picture-in-picture=(self), publickey-credentials-get=(), speaker-selection=(), sync-xhr=(), unoptimized-images=(), unsized-media=(), usb=(), screen-wake-lock=(self), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'unsafe-inline' 'self' nonce-ZGQ0ZmM1YzktMDcyOS00YWJiLTk5ZTMtZTc4ZTE3NjA2ODZl strict-dynamic pi.pardot.com app.storyblok.com recaptcha.net www.gstatic.com/recaptcha/ tagmanager.google.com *.googletagmanager.com *.cookie-script.com www.googleadservices.com www.google.com www.googletagmanager.com googleads.g.doubleclick.net cdn.cookie-script.com connect.facebook.net bat.bing.com snap.licdn.com static-exp1.licdn.com content.linkedin.com platform.linkedin.com cdn.leadinfo.net *.ldnfrpl.com *.clarity.ms bat.bing.net; style-src 'self' 'unsafe-inline' tagmanager.google.com fonts.googleapis.com *.licdn.com cdn.leadinfo.net; img-src 'self' data: blob: medialibrary.damen.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.nl googleads.g.doubleclick.net www.google.com google.com pagead2.googlesyndication.com www.facebook.net www.facebook.com bat.bi- strict-transport-security
max-age=31536000; includeSubDomains; preload