sefa.fr

.fr crawl

First seen 2026-04-20 · Last seen 2026-05-16 · ok HTTP/1.1 200 2002 ms crawled 2026-05-13

FR · 149.202.24.222 · AS16276 OVH SAS

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
PRESSES SEFA, fabricant de presses pour le marquage sur tout support de communication
Description
SEFA fabrique en France depuis 1973 des presses pour le marquage sur tout support de communication, par transfert à chaud ou impression directe.
Language
fr-fr
Generator
PrestaShop
Canonical
https://www.sefa.fr/fr/
Translations
  • en
  • es
  • fr

Technology

Server
nginx
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (2)

  • fonts.googleapis.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Address
BP 44, Z.I. de Pastabrac, 11260, ESPERANZA, France

Registration

Registrar
OVH
Created
1998-08-25
Expires
2027-02-27 284 days left
Updated
2026-03-31
Name servers
  • dns200.anycast.me
  • ns200.anycast.me

DNS records live

NS
  • dns200.anycast.me
  • ns200.anycast.me
MX
  • 10 mx01.cloud.vadesecure.com
  • 10 mx02.cloud.vadesecure.com
  • 10 mx03.cloud.vadesecure.com
  • 10 mx04.cloud.vadesecure.com
TXT
  • 1|www.sefa.fr
  • MS=ms19244306

Email authentication partial

SPF
v=spf1 a mx ptr include:spf.protection.outlook.com include:spf.mailjet.com include:mx.ovh.com -all
strict (-all)
DMARC
v=DMARC1; p=none
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3fixkDmUMF1x2t4nIZWlimbyXEaBiO2sFXTFAHBaHbJfceTZQFWXBKn9Z1UWwke/Pyrf7WVmtOr6dms0XVz…
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificate (current)

R13
from 2026-03-30 to 2026-06-28
Expires in 40 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.sefa.fr/fr/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https:; connect-src https: wss: http:; font-src https: data:; img-src https: data: blob:; frame-src https: blob:; frame-ancestors 'self'; worker-src blob: https: data: 'unsafe-inline' 'unsafe-eval'; form-action https: javascript:; script-src https: data: blob: 'unsafe-inline' 'unsafe-eval';style-src https: data: 'unsafe-inline'; base-uri 'self';
strict-transport-security
max-age=63072000; includeSubDomains; preload

Links to (10)

Linked from (2)