assurance-prevention.fr
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
Third-party hosts loaded (5)
- gmpg.org×1
- static.axept.io×1
- www.google.com×1
- www.gstatic.com×1
- www.suivi-matomo.fr×1
Social
Registration
- Registrar
- GANDI
- Created
- 2019-11-15
- Expires
- 2027-11-15 543 days left
- Updated
- 2025-10-19
- Name servers
-
- ns-158-a.gandi.net
- ns-245-c.gandi.net
- ns-95-b.gandi.net
DNS records live
- NS
-
- ns-158-a.gandi.net
- ns-245-c.gandi.net
- ns-95-b.gandi.net
- MX
-
- 1 mxa-0058ae01.gslb.pphosted.com
- 1 mxb-0058ae01.gslb.pphosted.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:spf.ffa-assurance.fr include:_mailcust.gandi.net include:spf.mandrillapp.com ?allneutral (?all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
R12
Expires in 48 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; script-src 'self' data: 'unsafe-eval' 'unsafe-inline' https://www.suivi-matomo.fr/ https://*.axept.io/ https://www.google.com/recaptcha/ https://www.gstatic.com/ https://cdn.jsdelivr.net/ *.instagram.com/ *.twitter.com/ *.x.com/ *.soundcloud.com/ *.vimeo.com/ *.ausha.co/ *.jquery.com/ cdnjs.cloudflare.com/ *.googletagmanager.com/ *.sk.ht/ *.youtube.com *.youtube-nocookie.com *.vimeo.com *.daylimotion.com ; style-src 'self' 'unsafe-inline' https://www.gstatic.com/ https://cdn.jsdelivr.net/- strict-transport-security
max-age=16070400; includeSubDomains; preload