zoegas.se
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- cdn.hypemarks.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- amsdns1.nestle.com
- aoadns1.nestle.com
- ctrdns1.nestle.com
- eurdns1.nestle.com
- MX
-
- 10 mail.telia.com
- Verified for
-
- Meta
Email authentication strong
- SPF
-
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 58 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src self localhost:8081; script-src 'self' *.usabilla.com *.doubleclick.net *.facebook.net *.nestle.com *.googleadservices.com *.nr-data.net *.pantheonsite.io *.zoegas.se *.newrelic.com 'unsafe-inline' 'unsafe-eval' *.adimo.co *.hypemarks.com *.rewe.de *.googletagmanager.com *.google-analytics.com *.bkrtx.com *.betrad.com *.rewe-static.de *.krxd.net *.evidon.com *.gigya.com *.youtube.com *.googleapis.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com *.googletagmanager.com localhost:8081 https://*.qualtrics.com *.qualtrics.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://code.jquery.com/; style-src 'self' 'unsafe-inline' *.adimo.co *.fontawesome.com fonts.googleapis.com fonts.gstatic.com https://cdnjs.cloudflare.com brand-ecommerce-assets.fusepump.com *.youtube.com cloud.typography.com *.google.com https://use.fontawesome.com d6tizftlrpuof.cloudfront.net cdn.cookielaw.org cookie-cdn.cookiepro.com *.- strict-transport-security
max-age=31536000; includeSubDomains; preload, max-age=300
Links to (6)
- facebook.com×1
- instagram.com×1
- nestle.se×1
- pinterest.com×1
- tiktok.com×1
- youtube.com×1