osce.org

.org crawl

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 899 ms crawled 2026-05-19

CA · 69.172.200.222 · AS19324 Dosarrest Internet Security LTD

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Organization for Security and Co-operation in Europe
Language
en
Generator
Drupal 11 (https://www.drupal.org)
Canonical
https://www.osce.org/
Translations
  • en

Technology

Server
nginx
CMS
Drupal
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Social

Contact

Email

Registration

Registrar
InterNetX GmbH
Created
1995-09-08
Expires
2026-09-07 110 days left
Updated
2025-10-22
Name servers
  • ns.nextlayer.at
  • ns2.nextlayer.at
  • nsany1.nextlayer.com
  • nsany2.nextlayer.com

DNS records live

NS
  • ns.nextlayer.at
  • ns2.nextlayer.at
  • ns3.nextlayer.com
  • nsany1.nextlayer.com
  • nsany2.nextlayer.com
MX
  • 10 oscemx.osce.org
TXT
Show 6 TXT records
  • mentimeter-cc00e638-547f-41bd-9976-4c5b41eb7ce6
  • cisco-ci-domain-verification=6f33f9d956402713c8ddd008ec92b7288ddb2797ba64932b1c2c7c01e3a54886
  • apple-domain-verification=zaXCTiEYGvIc2VAZ
  • adobe-idp-site-verification=fc8c22ef5f130b866edb25dcc46e7e10e3f4f31d949ed0188c542ecef987a544
  • ZOOM_verify_J7bLWTD5QIm6jE6-I8Mkcg
  • _globalsign-domain-verification=LOWe8o5b8M5jF91_NdqFCcp55JzNqaG9vaYxpU1A2p

Email authentication weak

SPF
v=spf1 ip4:194.8.63.171/32 ip4:194.8.63.165/32 ip4:194.8.63.166/32 a:oscemr.osce.org a:oscemr1.osce.org a:oscemr2.osce.org include:sendgrid.net include:eventsairmail.com include:inc.emailr.com ~all
softfail (~all)
DMARC
not published
DKIM
  • default: v=DKIM1; k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsUL/a8epvQ/1eC6uC9S78pIDg+Gi7rKd25cwlA2lzX05TRMZXE33rJtEUqiUsRxn9ds/Y8y9d3QaKUX…
selectors probed

Certificate (current)

emSign SSL CA - G1
from 2025-07-16 to 2026-08-10
Expires in 83 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.osce.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https: 'unsafe-inline' 'unsafe-eval' *.web.osce.org *.relaunch.web.osce.org; object-src 'none'; img-src https: data:
strict-transport-security
max-age=31557600

Links to (7)

Linked from (23)