ofb.gouv.fr

.fr crawl

First seen 2026-04-11 · Last seen 2026-05-20 · ok HTTP/1.1 200 2283 ms crawled 2026-05-19

US · 159.60.146.83 · AS35280 F5 Networks SARL

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Accueil | Office français de la biodiversité
Language
fr
Canonical
https://ofb.gouv.fr/
Translations
  • en
  • fr

Social

Registration

Registrar
OVH
Created
2019-12-17
Expires
2026-12-17 210 days left
Updated
2026-01-31
Name servers
  • dns14.ovh.net
  • ns14.ovh.net

DNS records live

NS
  • dns14.ovh.net
  • ns14.ovh.net
MX
  • 10 ofb-gouv-fr.mail.protection.outlook.com
Verified for
  • Brevo
  • Google
  • Zoom

Email authentication partial

SPF
v=spf1 include:spf.sendinblue.com include:spf.augure.com include:spf.tipimail.com include:spf.protection.outlook.com ip4:193.56.4.191/32 ip4:193.56.4.193/32 ip4:185.204.253.120 ip4:185.204.253.119 a -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:vuhk3p6c@rua.eu.dmarcmanager.app; ruf=mailto:vuhk3p6c@ruf.eu.dmarcmanager.app; fo=1; adkim=s; aspf=s
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAn8R+Mw6oMsPK02PSQfo/b0TLsps8N5heIYxFEiKEWA2DLXgDCcVBFP4ra8Ne1Pj5DUoowcUXGLEdK7…
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificate (current)

Trust Provider B.V. TLS RSA CA G1
from 2025-11-25 to 2026-12-14
Expires in 207 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://ofb.gouv.fr/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
object-src 'self' https://ssm-ecologie.shinyapps.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://svc.webspellchecker.net svc.webspellchecker.net platform.twitter.com http://platform.twitter.com http://platform.twitter.com/widgets.js www.tiktok.com https://www.tiktok.com https://www.tiktok.com/embed.js https://sf16-website-login.neutral.ttwstatic.com/obj/tiktok_web_login_static/tiktok/falcon/embed/embed_v1.0.13.js https://gvb.et-gv.fr/ufU638.js https://fxtt.ofb.gouv.fr/ufU638.js cdn.datatables.net cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com www.gstatic.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://svc.webspellchecker.net svc.webspellchecker.net platform.twitter.com http://platform.twitter.com www.tiktok.com https://www.tiktok.com sf16-website-login.neutral.ttwstatic.com https://sf16-website-login.neutral.ttwstatic.com
strict-transport-security
max-age=31536000

Links to (14)

Linked from (50)