groupesaintgatien.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
Third-party hosts loaded (1)
- gmpg.org×1
Social
Contact
- Phone
Registration
- Registrar
- OVH sas
- Created
- 2009-08-31
- Expires
- 2027-08-31 467 days left
- Updated
- 2025-01-10
- Name servers
-
- dns14.ovh.net
- ns14.ovh.net
DNS records live
- NS
-
- dns14.ovh.net
- ns14.ovh.net
- MX
-
- 10 groupesaintgatien-com.mail.protection.outlook.com
- TXT
-
7LRGSThF/s+xIJONdLXduoNuno8zkrvdvMjHurflBpd+/NJjXrNiIVbwl7BOLfvUDlgd1a+1j305QHIl9KeAUg==
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 a mx ip4:85.118.59.189 ip4:37.71.198.164 ip4:194.206.20.151 ip4:185.176.148.99 ip4:77.159.240.18 ip4:77.159.240.22 include:spf.cloud.vadesecure.com include:spf.protection.outlook.com include:mail.clinique-tivoli.com include:mail.polyforet.fr include:cpsureproxy.polyforet.fr include:210.201.2.109.rev.sfr.net ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GandiCert
Expires in 231 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com *.google.com *.gstatic.com *.google-analytics.com *.wp.com *.googleapis.com *.cloudflare.com *.youtube.com *.vimeo.com cdn.jsdelivr.net google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com maps.googleapis.com maps.google.com translate.googleapis.com translate.google.com www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: unpkg.com *.googleapis.com fonts.googleapis.com 'unsafe-inline' maps.googleapis.com maps.google.com translate.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: *.openstreetmap.org unpkg.com *.wp.com *.google.com *.google-analytics.com *.google.fr *.elementor.com *.cartocdn.com qr-code.ithemes.com s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com data: blob: google-analytics.com www.google-analy- strict-transport-security
max-age=31536000; includeSubDomains, max-age=63072000