zimvie.eu
HTML metadata
Technology
- Cookie consent
-
- OneTrust
Third-party hosts loaded (3)
- cdn.cookielaw.org×2
- assets.adobedtm.com×1
- vjs.zencdn.net×1
Social
DNS records live
- NS
-
- udns1.cscdns.net
- udns2.cscdns.uk
- MX
-
- 10 custmx.cscdns.net
- TXT
-
Show 6 TXT records
google-site-verification=kQddKXbUP-cUZIuJY5DInoITTsb5nK3JjgkhBiYbJzwgoogle-site-verification=weDgVsg2MPW1N0-OvGwBYGuGmcVn_6V_ZyO-MjUegZg_j6knhqceccti4vn6hduar4kx889l0is_k4tlhqy8ndwjahul9alzd2q65kv29k6hv3nh0mxm4l6bmvkx1bwsf309vmxm8cgrgmnch0jq6h2zg87h6b9b6lqtsttz3pj
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 205 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; font-src 'self' https://*.gstatic.com https://*.typekit.net data:; script-src 'self' https://*.bing.com https://*.clarity.ms https://*.doubleclick.net https://*.hs-scripts.com https://*.hsforms.net https://*.hsforms.com https://*.hs-banner.com https://*.hsadspixel.net https://*.hs-analytics.net https://*.hscollectedforms.net https://*.hubspot.com https://*.scene7.com https://*.google.com https://google.com https://*.google-analytics.com https://*.googletagmanager.com https://*.adobedtm.com https://*.cookielaw.org https://*.facebook.net https://*.googleapis.com https://*.gstatic.com https://*.vimeo.com https://*.vimeocdn.com https://*.licdn.com https://*.typekit.net https://*.zencdn.net https://*.cloudfront.net https://*.amazonaws.com https://*.oct8ne.com https://*.stackadapt.com 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: https://*.zimvie.com https://*.scene7.com https://*.omtrdc.net https://*.google-analytics.com https://*.googletagmanager.com https://*.goo- strict-transport-security
max-age=63072000; includeSubdomains;