vacaf.org
HTML metadata
Registration
- Registrar
- Gandi SAS
- Created
- 2000-11-27
- Expires
- 2026-11-27 192 days left
- Updated
- 2025-10-26
- Name servers
-
- ns-105-b.gandi.net
- ns-41-a.gandi.net
- ns-49-c.gandi.net
DNS records live
- NS
-
- ns-105-b.gandi.net
- ns-41-a.gandi.net
- ns-49-c.gandi.net
- MX
-
- 10 mail.klio.me
- TXT
-
brevo-code:c47d294ac11220b59db5461258a77c35
Email authentication strong
- SPF
-
v=spf1 ip4:195.88.181.185/32 include:spf.mailjet.com include:mailgun.org include:spf.brevo.com mx ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; fo=1; ri=3600; rua=mailto:ed4a1022@dmarc.mailgun.org,mailto:b414ec40@inbox.ondmarc.com; ruf=mailto:ed4a1022@dmarc.mailgun.org,mailto:b414ec40@inbox.ondmarc.com;policy: reject (enforced) - DKIM
-
- mail:
v=DKIM1;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuRuTXm43jHPiPeu58DmEJAQDdD42IF6uVzPQcWyMvtjbEzJoWPlMfrbg4YIQzO1IF9dnMHHMmJX3tzrfeXyNz4…
selectors probed - mail:
Certificate (current)
R13
Expires in 84 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- content-security-policy
default-src vacaf.org *.vacaf.org api-adresse.data.gouv.fr api.insee.fr mailto: tel: ; font-src 'self' fonts.gstatic.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' api-adresse.data.gouv.fr; img-src 'self' https://*.openstreetmap.fr https://vacaf.org https://*.vacaf.org data:; frame-ancestors 'self' https://vacaf.org https://*.vacaf.org https://api-adresse.data.gouv.fr;- strict-transport-security
max-age= 63072000; includeSubDomains; preload