myhumankit.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
Third-party hosts loaded (2)
- cdn.jsdelivr.net×3
- static.addtoany.com×2
Social
Contact
- Phone
- Address
- avenue du Bois Labbé – CS 44238
Registration
- Registrar
- OVH sas
- Created
- 2015-10-09
- Expires
- 2026-10-09 142 days left
- Updated
- 2026-04-15
- Name servers
-
- aida.ns.cloudflare.com
- colin.ns.cloudflare.com
DNS records live
- NS
-
- aida.ns.cloudflare.com
- colin.ns.cloudflare.com
- MX
-
- 1 smtp.google.com
- TXT
-
Sendinblue-code:53355497594d628285f52af2b65c016fca3-bb4a214f35e3443385fd4b94252e1798
Email authentication weak
- SPF
-
v=spf1 ip4:185.26.126.90 ip6:2001:4b98:dc2:43:216:3eff:feec:965d include:mx.ovh.com include:spf.sendinblue.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - mail:
Certificate (current)
E7
Expires in 70 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' data: cdn.jsdelivr.net *.kinstacdn.com www.google-analytics.com static.addtoany.com platform.twitter.com; style-src 'self' 'unsafe-inline' *.kinstacdn.com fonts.googleapis.com cdn.jsdelivr.net; connect-src 'self'; media-src 'self'; worker-src 'self' blob:; object-src 'none'; form-action 'self' *.youtube.com *.dailymotion.com *.vimeo.com; img-src 'self' data: secure.gravatar.com *.kinstacdn.com ssl.google-analytics.com s.w.org *.olevmedia.net myhumankit.org; base-uri 'self'; frame-src 'self' static.addtoany.com platform.twitter.com *.youtube.com *.dailymotion.com *.vimeo.com *.google.com; font-src 'self' data: fonts.gstatic.com myhumankit.org *.kinstacdn.com myhumankit.kinsta.cloud; manifest-src 'self'; default-src 'self';