orias.fr

.fr crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 794 ms crawled 2026-05-18

FR · 194.5.108.182 · AS3259 Docapost BPO SAS

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Orias

Technology

Analytics
  • Google Tag Manager
  • Matomo

Third-party hosts loaded (5)

  • cdn.jsdelivr.net×4
  • code.jquery.com×2
  • www.google.com×2
  • agiravie.matomo.cloud×1
  • www.googletagmanager.com×1

Registration

Registrar
GANDI
Created
2006-07-24
Expires
2026-11-25 190 days left
Updated
2025-10-30
Name servers
  • ns-127-a.gandi.net
  • ns-145-c.gandi.net
  • ns-253-b.gandi.net

DNS records live

NS
  • ns-127-a.gandi.net
  • ns-145-c.gandi.net
  • ns-253-b.gandi.net
MX
  • 0 orias-fr.mail.protection.outlook.com
TXT
Show 4 TXT records
  • MS=ms27266089
  • google-site-verification=iYtOEYBfFsHam72VX-15v50LH7Rqtwn_xepgoelQRGU
  • Sendinblue-code:55af608d8ccb1ecab8db1124a953de41
  • bw=AUjbSH12r02oZYb40yjqTsHuQdb4EcyW8raass6VIYri

Email authentication partial

SPF
v=spf1 a ip4:89.185.42.128 ip4:194.5.116.235 ip4:194.5.108.155 include:_spf.mail.as8677.net include:spf.mailjet.com include:spf.sendinblue.com include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1;p=none;sp=none;pct=100; rua=mailto:dmarc@gpsa.fr; ruf=mailto:dmarc@gpsa.fr
policy: none (monitoring only) · sp=none
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw6hJJM7n5yTK3Vafz+IXqi/JFGtCLkcP74feOPksKb6nc+53yHCl5rA+ePsSwaggI/yRMtj9am+y1n…
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificate (current)

Gandi RSA Domain Validation Secure Server CA 3
from 2025-06-17 to 2026-07-10
Expires in 52 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://orias.fr/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; font-src https: data: wss: 'unsafe-inline' 'unsafe-eval', style-src 'self' 'unsafe-inline';frame-ancestors 'self'; form-action 'self' http://orias.fr https://payment-webinit.mercanet.bnpparibas.net https://payment-webinit-mercanet.test.sips-atos.com https://payment-webinit-mercanet.test.sips-services.com; img-src 'self' data:;object-src 'self'
strict-transport-security
max-age=31536000; includeSubDomains

Links to (1)

Linked from (42)