novae-recrute.com
HTML metadata
Technology
- Server
- nginx
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×2
- fonts.gstatic.com×1
Contact
- Address
- 130 boulevard Haussmann, 75008, Paris, Ile-de-France, FR
Registration
- Registrar
- Gandi SAS
- Created
- 2022-10-25
- Expires
- 2026-10-25 158 days left
- Updated
- 2025-08-18
- Name servers
-
- ns-135-a.gandi.net
- ns-199-b.gandi.net
- ns-86-c.gandi.net
DNS records live
- NS
-
- ns-135-a.gandi.net
- ns-199-b.gandi.net
- ns-86-c.gandi.net
- MX
-
- 10 spool.mail.gandi.net
- 50 fb.mail.gandi.net
- Verified for
-
- Brevo
Email authentication partial
- SPF
-
v=spf1 include:_mailcust.gandi.net ?allneutral (?all) - DMARC
-
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.compolicy: none (monitoring only) - DKIM
-
- mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - mail:
Certificate (current) wrong cert
R13
Expires in 81 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' api.arvow.com analytics.novae.dev novae-group.containers.piwik.pro client.crisp.chat static.axept.io www.clarity.ms www.google-analytics.com optimize.google.com www.googleadservices.com www.googletagmanager.com; style-src 'self' 'unsafe-inline' client.crisp.chat optimize.google.com fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' wss://client.relay.crisp.chat https://*.tiles.mapbox.com https://api.mapbox.com https://events.mapbox.com analytics.novae.dev novae-group.containers.piwik.pro novae-group.piwik.pro api.axept.io client.axept.io www.youtube.com *.clarity.ms *.google-analytics.com adservice.google.com *.algolia.net *.algolianet.com; font-src 'self' client.crisp.chat fonts.gstatic.com; frame-src 'self' optimize.google.com www.youtube.com; img-src 'self' www.gravatar.com i0.wp.com blob: data: axeptio.imgix.net googleads.g.doubleclick.net www.google-analytics.com optimize.google.com www.g- strict-transport-security
max-age=300; includeSubDomains; preload; always;