toquedazur.fr

.fr crawl

First seen 2026-04-20 · Last seen 2026-05-13 · ok HTTP/1.1 200 1267 ms crawled 2026-05-13

FR · 212.95.67.169 · AS8839 SDV6TM SAS

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Toque D'Azur - Épices & bases culinaires
Language
fr
Translations
  • fr

Open Graph

title
Toque D'Azur - Épices & bases culinaires

Technology

Server
Apache
Fonts
  • Adobe Fonts
  • Google Fonts

Third-party hosts loaded (2)

  • fonts.googleapis.com×2
  • use.typekit.net×2

Social

Contact

Phone

Registration

Registrar
GANDI
Created
2007-03-13
Expires
2026-06-18 28 days left
Updated
2025-11-13
Name servers
  • ns-181-a.gandi.net
  • ns-77-b.gandi.net
  • ns-88-c.gandi.net

DNS records live

NS
  • ns-181-a.gandi.net
  • ns-77-b.gandi.net
  • ns-88-c.gandi.net
MX
  • 0 toquedazur-fr.mail.protection.outlook.com
Verified for
  • Microsoft 365

Email authentication weak

SPF
v=spf1 a:www.toquedazur.fr ip4:66.155.76.28 ip4:212.95.71.137 include:spf.protection.outlook.com include:spf.emailsignatures365.com include:spf.mailjet.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

RapidSSL TLS RSA CA G1
from 2025-06-03 to 2026-06-27
Expires in 37 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://toquedazur.fr/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), geolocation=(), fullscreen=(self "https://www.dailymotion.com" "https://*.vimeo.com" "https://www.youtube.com" "https://www.youtube.be"), autoplay=(self "https://www.dailymotion.com" "https://*.vimeo.com" "https://www.youtube.com" "https://www.youtube.be"), camera=(), display-capture=()
x-content-type-options
nosniff
content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'

Links to (4)

Linked from (1)