isae-supmeca.fr
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Adobe Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (4)
- cdn.jsdelivr.net×3
- use.typekit.net×2
- www.youtube.com×2
- matomo-supmeca.demo-3octets.fr×1
Social
Registration
- Registrar
- GIP RENATER
- Created
- 2021-02-24
- Expires
- 2027-02-24 281 days left
- Updated
- 2026-03-31
- Name servers
-
- ns1.supmeca.fr
- ns2.supmeca.fr
DNS records live
- NS
-
- ns1.supmeca.fr
- ns2.supmeca.fr
- MX
-
- 0 isaesupmeca-fr01b.mail.protection.outlook.com
Email authentication weak
- SPF
-
v=spf1 ip4:195.83.207.194 include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA62oQqV275Yq/We+PeCueQd+Td3N1t075i/3k/w2te1PwfdosL8NFWnMtFth28uEDmXUdOxse1w48RA…
selectors probed - selector1:
Certificate (current)
E7
Expires in 40 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- permissions-policy
autoplay=(), encrypted-media=(), fullscreen=(), geolocation=(), microphone=(), midi=()- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' *.isae-supmeca.fr *.groupe-isae.fr matomo-supmeca.demo-3octets.fr blob: *.demo-3octets.fr *.bokeh.org *.3octets.fr *.google.com *.tradedoubler.com *.sharethis.com *.addthis.com *.moatads.com *.addthisedge.com *.googletagmanager.com *.facebook.com *.twitter.com t.co *.gstatic.com *.hotjar.com *.smartlook.com *.w.org *.facebook.net *.ads-twitter.com *.licdn.com *.sk.ht *.cloudflare.com *.jquery.com *.bootstrapcdn.com *.gravatar.com *.googleapis.com *.jsdelivr.net *.printfriendly.com *.kxcdn.com *.vimeocdn.com *.hs-analytics.net *.securitymetrics.com *.google-analytics.com; style-src 'self' 'unsafe-inline' blob: *.jsdelivr.net *.googleapis.com *.bootstrapcdn.com *.gstatic.com *.typekit.net *.cloudflare.com *.icons8.com *.vimeocdn.com; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.isae-supmeca.fr *.groupe-isae.fr matomo-supmeca.demo-3octets.fr blob: *.bokeh.org wpml.org toolset.com *.eudonet.com *.3octets.fr *.cdninstagram.com *.twimg- strict-transport-security
max-age=31536000; includeSubDomains