moralscore.org
HTML metadata
Technology
- Server
- gunicorn
- CMS
- Gatsby
- Stack
- Django
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×4
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1fkl.name.com
- ns2qvz.name.com
- ns3jwx.name.com
- ns4bht.name.com
- MX
-
- 10 mx1.titan.email
- 20 mx2.titan.email
- TXT
-
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCQQZGLNX4QMk6xIb+ZN2hXGbzJCXKEv6UyY2CmluOb0xEHn/qxGJ1jr4exQsWawGSkr97vgsnM72ZdAXfhGs9acH3PDT4k8cA//uF2EnQThOF1mFYMiN5Kv6S7heORq9qQtWFfkzTWUyvYcSxptryUAPAd6oUWStrABMzWbRuy2QIDAQAB
Email authentication partial
- SPF
-
v=spf1 include:spf.mailjet.com include:spf.titan.email ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; sp=none; rua=mailto:dmarc@mailinblue.com!10m; ruf=mailto:dmarc@mailinblue.com!10m; rf=afrf; pct=100; ri=86400policy: none (monitoring only) · sp=none - DKIM
-
- mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - mail:
Certificate (current)
E8
Expires in 26 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
geolocation=(self), microphone=(), camera=(), payment=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://unpkg.com https://ajax.googleapis.com https://js.stripe.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://unpkg.com https://cdnjs.cloudflare.com; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com data:; img-src 'self' data: https: blob:; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://region2.google-analytics.com https://region3.google-analytics.com https://region4.google-analytics.com https://region5.google-analytics.com https://api.moralscore.org https://sentry.io https://nominatim.openstreetmap.org https://unpkg.com https://api.stripe.com; frame-src https://js.stripe.com https://checkout.stripe.com; object-src 'none'; base-uri 'self'; form-action 'self' https://checkout.stripe.com; frame-ancestors 'none'; upgrade-insecure- cross-origin-opener-policy
same-origin
Links to (38)
- vivamagazine.fr×1
- usine-digitale.fr×1
- twitter.com×1
- theconversation.com×1
- tf1info.fr×1
- rue89lyon.fr×1
- rtl.fr×1
- reporterre.net×1
- positivr.fr×1
- nouvelobs.com×1
- nicematin.com×1
- midilibre.fr×1
- linkedin.com×1
- linforme.com×1
- linfodurable.fr×1
- liberation.fr×1
- lesechos.fr×1
- leprogres.fr×1
- leparisien.fr×1
- lemonde.fr×1
- lefigaro.fr×1
- lci.fr×1
- latribune.fr×1
- ladn.eu×1
- ladepeche.fr×1
- la-croix.com×1
- instagram.com×1
- google.com×1
- franceinter.fr×1
- franceinfo.fr×1
- france.tv×1
- forbes.fr×1
- facebook.com×1
- charliehebdo.fr×1
- capital.fr×1
- bfmtv.com×1
- apple.com×1
- 01net.com×1