framatome.com
HTML metadata
Technology
- CMS
- WordPress
- Cookie consent
-
- OneTrust
Third-party hosts loaded (1)
- cdn.cookielaw.org×3
Social
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 1997-12-09
- Expires
- 2026-12-08 203 days left
- Updated
- 2025-12-04
- Name servers
-
- dns1.areva.com
- dns2.areva.com
DNS records live
- NS
-
- dns1.areva.com
- dns2.areva.com
- MX
-
- 10 mail.areva.com
- 10 mail2.areva.com
- 10 smtpin1.areva.com
- 10 smtpin2.areva.com
- TXT
-
Show 21 TXT records
atlassian-domain-verification=Q9QfQOO2l5kZ9xYfSpmGmF3DJrE1XMukdb7uYoPJVuPFGAJHQjGYnH8lkfA1uhxi_taksx9mxgp7696xvda93psotjdlxeyztKtWnpFDYZNezkIJfVadCRq4vKxm2Edla01eePNmrASKPv6VJZllL2F72No66E+slF9YxSLKjd3WEH7NPQgeJw==10951ab606-5f75-4b52-aa69-37dbfc095014atlassian-sending-domain-verification=2b2c3911-a61b-49a9-abd9-747c4ff689c6_ja5n2n20h2xgrxblg6jfs6u6odjag9fMS=E4066BA9A94A938D33AF57A30212DFAACC768C7A_b2inkpjfz3fpoii7kmkf2tnrs5q2se3cisco-ci-domain-verification=2a629e9180d54723194c42ad8fd35e6e29ff3b53858f200185db065df89cbd48_0frmvy1571oqf9kxgkdwhmevnkjjq46apple-domain-verification=xkV2LgWPLUqenX4V_92m41n34w1p5aj8vq0z6pyzaopd5ihyf39cdtt40287njdrs17tty54zs5kh743QuoVadis=f198e222-22b2-4005-8a4b-429f397ef79bQuoVadis=7d14bffa-97c1-40f0-a553-3cf1abe2f578zddfxr2lqbb9rq8f3wqm8cd9cyvn54pqQuoVadis=261f6243-7dca-4e28-8d19-4a40eb66f73aMS=ms59074555MS=ms60346376_t7tykc0cnbvopw8vzwov8nb0mwfwzz5adobe-idp-site-verification=1b423da3cfef1ba2e4eed0e29bf60beb5971d5d7c95333b177bfc975730ad5b7
Email authentication strong
- SPF
-
v=spf1 ip4:160.84.253.64/28 ip4:193.57.67.0/29 ip4:80.75.159.31 ip4:80.75.159.43 ip4:80.75.158.1 ip4:134.128.84.30 include:spf.protection.outlook.com include:_spf.profils.org -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=none; rua=mailto:gistsindmarcreport@si-nergie.tech,mailto:vqczu5hl@ag.eu.dmarcian.com; ruf=mailto:gistsindmarcreport@si-nergie.tech,mailto:vqczu5hl@fr.eu.dmarcian.com; fo=1; adkim=r; aspf=rpolicy: quarantine · sp=none - DKIM
- no key found at common selectors
Certificate (current)
DigiCert G2 TLS EU RSA4096 SHA384 2022 CA1
Expires in 145 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin, no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
attribution-reporting=(), browsing-topics=(), camera=(), clipboard-read=(), display-capture=(), geolocation=(), hid=(), identity-credentials-get=(), idle-detection=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), on-device-speech-recognition=(), otp-credentials=(), payment=(), publickey-credentials-create=(), publickey-credentials-get=(self), screen-wake-lock=(), serial=(), storage-access=(), usb=(), window-management=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' framatome.epresspack.online www.youtube-nocookie.com youtube-nocookie.com youtube.com www.youtube.com; base-uri 'self'; object-src 'none'; frame-ancestors 'self' www.framatome.com; img-src 'self' data: blob: https: maps.gstatic.com *.googleapis.com *.gstatic.com; font-src 'self' data: https: fonts.gstatic.com; style-src 'self' 'unsafe-inline' https: fonts.googleapis.com maps.googleapis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' framatome.epresspack.online symposium.dashboard.davenhr.com player.vimeo.com widget.tagembed.com www.rec.framatome.com tag.aticdn.net www.googletagmanager.com cdn.jsdelivr.net cdn.cookielaw.org www.youtube.com maps.googleapis.com *.googleapis.com; worker-src 'self' blob:; connect-src 'self' https: cdn.cookielaw.org symposium.dashboard.davenhr.com symposium.dashboard.data-driven.fr maps.googleapis.com *.googleapis.com; form-action 'self'; upgrade-insecure-requests; block-all-mixed-content- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin