ecca.eu

.eu crawl

First seen 2026-04-15 · Last seen 2026-05-16 · ok HTTP/1.1 200 1092 ms crawled 2026-05-10

PL · 195.8.106.71 · AS34431 Opteam S. A.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
ECCA – Student eID | European Campus Card Association
Description
ECCA's mission is to connect HEIs through modern identification systems. We support knowledge exchange, research into campus card technology and transnational cooperation.
Language
en
Canonical
https://ecca.eu/

Open Graph

title
ECCA – Student eID | European Campus Card Association
description
ECCA's mission is to connect HEIs through modern identification systems. We support knowledge exchange, research into campus card technology and transnational cooperation.

Technology

Server
nginx

DNS records live

NS
  • ns1.bdm.microsoftonline.com
  • ns2.bdm.microsoftonline.com
  • ns3.bdm.microsoftonline.com
  • ns4.bdm.microsoftonline.com
MX
  • 0 ecca-eu.mail.protection.outlook.com
TXT
  • google-site-verification=n2lFrYCgBmxjlZiQcMcd-ebGpsT3OhgsKqgIWnZEpqA
  • mscid=fjFemNyvGrBMWxJuyq1PprwnHfJHPJvg/k1YGmwcvP0WbXs5jTV1tNTQsPmzNQZ0xGJa1Wls/0Ce4AFiJOkkYg==

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com include:spf.mailjet.com include:servers.mcsv.net a:mailsrvc.up.pt a:mail-out.darklite.ie ~all
softfail (~all)
DMARC
not published
DKIM
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9LW0bb+4Pcfih38ax4aPAaZob59RVpAvd4YBXeZ6jGON88SZUMRqt8slIMWCgBEJdFkeVTVTCxKWL4+/2sw…
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed

Certificate (current)

R13
from 2026-04-01 to 2026-06-30
Expires in 42 days

HTTP security headers

Header hygiene 60/100 Checked live page: https://ecca.eu/

present
  • strict-transport-security
  • content-security-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
frame-ancestors 'self'; default-src 'self' data: blob: *.openstreetmap.org ; img-src data: blob: * *.momentjs.net *.doubleclick.net *.facebook.com *.facebook.net *.google-analytics.com *.googlesyndication.com *.gstatic.com *.hotjar.com *.twitter.com *.youtube.com ajax.googleapis.com ; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com ; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.gstatic.com *.easypack24.net *.tiktok.com *.ttwstatic.com *.inpost.pl ; frame-src 'self' *.google.com *.facebook.com *.youtube.com *.instagram.com *.twitter.com *.easypack24.net *.inpost.pl *.tiktok.com *.ttwstatic.com *.googletagmanager.com *.cloudflare.com *.openstreetmap.org ; script-src 'self' blob: 'unsafe-inline' 'unsafe-eval' *.cloudflare.com *.momentjs.com momentjs.com *.google-analytics.com *.google.com connect.facebook.net *.instagram.com *.twitter.com *.googletagmanager.com *.hotjar.com *.gstatic.com *.easypack24.net *.tiktok.com *.ttwstatic.com *.inpost.pl ; connect-src 's
strict-transport-security
max-age=31536000; includeSubDomains; preload, max-age=31536000;

Links to (26)

Linked from (4)