yellohvillage.it
HTML metadata
Technology
- Server
- YellohVillage
Third-party hosts loaded (8)
- img.yellohvillage.fr×20
- widgets.yellohvillage.fr×3
- assets.adobedtm.com×1
- www.yellohvillage.co.uk×1
- www.yellohvillage.de×1
- www.yellohvillage.es×1
- www.yellohvillage.fr×1
- www.yellohvillage.nl×1
Social
Contact
- Phone
DNS records live
- NS
-
- nsa.perf1.fr
- nsb.perf1.com
- nsc.perf1.com
- MX
-
- 0 mx3.nameshield.com
- 10 mx4.nameshield.net
- TXT
-
tcgwbps12lwtstx2j6kk99z0nzd2491537mg4dj70nn15qy17lr5050pyh3llrn0llpmp04zdg78qpvtw71b5hlf5p9vbywr
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 include:trustpilotservice.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 82 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(), geolocation=(self), fullscreen=(self "https://www.youtube.com"), autoplay=("https://www.youtube.com"), camera=(), display-capture=(self)- x-content-type-options
nosniff- content-security-policy
frame-src https://*.yellohvillage.es https://*.yellohvillage.co.uk https://*.yellohvillage.de https://*.yellohvillage.it https://*.yellohvillage.fr https://*.yellohvillage.nl https://www.youtube.com https://*.fls.doubleclick.net https://td.doubleclick.net https://www.google.com https://yellohvillage.demdex.net https://*.admin.yellohvillage.fr https://admin.yellohvillage.fr https://*.iadvize.com https://*.criteo.com https://static.criteo.net https://*.facebook.com https://*.omtrdc.net https://*.contentsquare.net https://*.contentsquare.com https://*.apidae-tourisme.com https://*.adoberesources.net https://*.zenchef.com https://*.adobedc.net https://tags.creativecdn.com https://ams.creativecdn.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://*.hotjar.com https://*.addthis.com https://*.fr.datacamping.com https://*.es.datacamping.com https://*.de.datacamping.com https://*.it.datacamping.com https://*.en.datacamping.com https://*.nl.datacamping.com https://cdn.mouseflow.c- strict-transport-security
max-age=31536000; includeSubDomains