yakimachief.eu
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- p0lpjh-jlfn222rqlrs.cloudmaestro.com×30
- x0huvt-jlfn222rqlrs.cloudmaestro.com×18
- shb7cz-jlfn222rqlrs.cloudmaestro.com×12
- assets.juicer.io×4
- maxcdn.bootstrapcdn.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- kara.ns.cloudflare.com
- norm.ns.cloudflare.com
- Verified for
-
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 27 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src-elem 'self' 'unsafe-inline' *.juicer.io *.fullstory.com fullstory.com maps.googleapis.com *.youtube.com *.binaryanvil.work *.yakimachief.com *.yakimachief.eu *.googletagmanager.com *.cdninstagram.com *.cloudmaestro.com *.google.com.ua *.google.com.ph *.google.com.us *.google.com.eu *.google-analytics.com *.doubleclick.net *.trackedweb.net *.datadoghq-browser-agent.com datadoghq-browser-agent.com *.browser-intake-datadoghq.com.com browser-intake-datadoghq.com *.google.com *.gstatic.com *.facebook.net *.facebook.com *.shipperhq.com *.trackedlink.net *.adobedtm.com *.paypal.com *.paypalobjects.com *.aptrinsic.com; font-src *.bootstrapcdn.com *.cdn-apple.com fonts.googleapis.com fonts.gstatic.com *.juicer.io *.cloudmaestro.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com *.yakimachief.eu 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-p- strict-transport-security
max-age=31536000; includeSubDomains; preload- content-security-policy-report-only
base-uri https://r1-t.trackedlink.net https://www.datadoghq-browser-agent.com; connect-src www.google.com.ua; img-src https://www.googletagmanager.com data: https://*.cloudmaestro.com https://shop.yakimachief.com https://yakimachief.eu https://yakimachief.com https://www.yakimachief.eu https://webscale-prod.yakimachief.com https://www.yakimachief.com *.analytics.google.com *.google-analytics.com; report-uri /.webscale/csp-report