arnaudligny.fr
HTML metadata
Technology
- Server
- statichost.eu
- Analytics
-
- Cloudflare Insights
- Fonts
-
- Google Fonts
Third-party hosts loaded (10)
- fonts.googleapis.com×4
- ayrcxgimor.cloudimg.io×2
- webmention.io×2
- fonts.gstatic.com×1
- fr.linkedin.com×1
- gazuji.com×1
- github.com×1
- scripts.simpleanalyticscdn.com×1
- static.cloudflareinsights.com×1
- twitter.com×1
Social
Registration
- Registrar
- GANDI
- Created
- 2007-09-26
- Expires
- 2026-09-26 128 days left
- Updated
- 2025-09-25
- Name servers
-
- ns-171-b.gandi.net
- ns-173-c.gandi.net
- ns-71-a.gandi.net
DNS records live
- NS
-
- ns-171-b.gandi.net
- ns-173-c.gandi.net
- ns-71-a.gandi.net
- MX
-
- 10 spool.mail.gandi.net
- 50 fb.mail.gandi.net
- TXT
-
keybase-site-verification=UvAeXIk5pOWiqrQie6mK9K2WufSXI-ZHFrFa91578gQ
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 include:_mailcust.gandi.net ?allneutral (?all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
ZeroSSL ECC Domain Secure Site CA
Expires in 32 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; object-src 'self'; img-src 'self' data: www.google-analytics.com *.twitter.com *.twimg.com *.netlify.com *.netlify.app res.cloudinary.com aligny.twic.pics aligny.imgix.net ayrcxgimor.cloudimg.io; script-src 'self' 'unsafe-inline' *.arnaudligny.fr *.netlify.com *.googleapis.com www.google-analytics.com www.googletagmanager.com *.twitter.com *.twimg.com *.noti.st *.notist.cloud static.cloudflareinsights.com gist.github.com giscus.app; style-src 'self' 'unsafe-inline' *.arnaudligny.fr *.netlify.com *.googleapis.com *.twitter.com github.githubassets.com giscus.app; font-src 'self' data: fonts.gstatic.com; frame-src 'self' *.twitter.com docs.google.com www.youtube.com www.youtube-nocookie.com noti.st *.notist.cloud giscus.app; connect-src 'self' www.google-analytics.com cloudflareinsights.com/cdn-cgi/rum res.cloudinary.com aligny.twic.pics aligny.imgix.net ayrcxgimor.cloudimg.io *.netlify.app fonts.googleapis.com fonts.gstatic.com static.cloudflareinsights.com identity.n- strict-transport-security
max-age=31536000; includeSubDomains; preload