athenora-academy.com
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- cdnjs.cloudflare.com×5
- cdn.jsdelivr.net×2
- fonts.googleapis.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- avenue de Cortenbergh1000
Registration
- Registrar
- OVH sas
- Created
- 2020-06-05
- Expires
- 2026-06-05 15 days left
- Updated
- 2025-06-06
- Name servers
-
- dns109.ovh.net
- ns109.ovh.net
DNS records live
- NS
-
- dns109.ovh.net
- ns109.ovh.net
- MX
-
- 1 mx1.mail.ovh.net
- 100 mx3.mail.ovh.net
- 5 mx2.mail.ovh.net
- TXT
-
1|www.athenora-academy.com
Email authentication weak
- SPF
-
v=spf1 a mx ip4:83.166.130.240 include:mx.ovh.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3JrpTIfkqB/y6L79R/FglXv6pRoltn0x/clQ1Elv+bDEwEfCZof2Um1baTZo9VKqopX4elbyQ86iVM19X7… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDlBfOLQ9tq61mk1UvvEi+9MogqZv/AwXYznnkU1SulJNi0mf5HcJ0ReNk9Xt06M+cBdJTartYbrazAiKcW7oBwL…
selectors probed - s1:
Certificate (current)
R12
Expires in 28 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'report-sample' 'self' 'unsafe-inline' https://cdn.tiny.cloud https://cdn.jsdelivr.net https://www.gstatic.com https://www.google.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://cdn.datatables.net https://cdnjs.cloudflare.com https://www.google-analytics.com https://www.googletagmanager.com;style-src 'report-sample' 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdn.tiny.cloud https://cdn.datatables.net https://cdnjs.cloudflare.com https://fonts.googleapis.com;object-src 'none';base-uri 'self';connect-src 'self' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdn.tiny.cloud https://cdn.datatables.net https://stats.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://consentcdn.cookiebot.com;font-src 'self' data: https://fonts.gstatic.com;frame-src 'self' https://www.google.com https://www.youtube.com;img-src 'self' https://*.ytimg.com https://*.tinymce.com https://imgsct.cookiebot.- strict-transport-security
max-age=31536000; includeSubDomains