surlechamp.co
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (1)
- cdn.socleo.org×32
Contact
- Phone
DNS records live
- NS
-
- ns-224-b.gandi.net
- ns-46-a.gandi.net
- ns-77-c.gandi.net
- MX
-
- 1 groupe-scael.in.tmes.trendmicro.eu
- TXT
-
tmes=e31439c6e9899d8cfceb8891e22fc131
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.tmes.trendmicro.eu include:spf-eu.letsignit.com include:spfcloud.letsignit.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:groupe-scael@dmarcrua.tmes.trendmicro.eupolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMhZmQQSPDYMQ03qmzUvO0BoPzhhd9Tt2UQGWUVRG5i6JcSlD+aQH1iGjnevspfn2OdURsM+aHLR90bEu6QG…
selectors probed - selector1:
Certificate (current)
R13
Expires in 79 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src https: data: *; script-src https://cdn.socleo.org https://cdn.panierlocal.org https://cdn.socleo.org http://*.google.com https://*.google.com http://*.google-analytics.com https://*.google-analytics.com https://*.apis.google.com https://*.googleapis.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net http://*.twitter.com https://twitter.com https://*.twitter.com https://*.twimg.com http://connect.facebook.net https://connect.facebook.net http://*.ak.fbcdn.net https://*.ak.fbcdn.net https://instagram.com https://www.instagram.com https://cdnjs.cloudflare.com https://unpkg.com https://js.stripe.com https://*.brevo.com https://widget.mondialrelay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' *; img-src data: blob: *; frame-ancestors 'self'; report-uri /enl/csp_report.jsp- strict-transport-security
max-age=15768000
surlechamp.co