zaffra.com

.com crawl

First seen 2026-04-16 · Last seen 2026-05-07 · ok HTTP/1.1 200 679 ms crawled 2026-05-11

NL · 143.244.199.125 · AS14061 DigitalOcean, LLC

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Zaffra, powering aviation’s transition to sustainable fuel
Description
Zaffra drives the future of flight through advanced technology, expert partnerships, and sustainable aviation fuel solutions that enable large-scale decarbonisation across the industry.
Language
en
Canonical
https://zaffra.com

Open Graph

url
https://zaffra.com
title
Zaffra, powering aviation’s transition to sustainable fuel
description
Zaffra drives the future of flight through advanced technology, expert partnerships, and sustainable aviation fuel solutions that enable large-scale decarbonisation across the industry.

Technology

CMS
Drupal
Analytics
  • Google Tag Manager
Cookie consent
  • Cookiebot

Third-party hosts loaded (2)

  • consent.cookiebot.com×1
  • www.googletagmanager.com×1

Registration

Registrar
GoDaddy.com, LLC
Created
2007-01-08
Expires
2028-01-08 597 days left
Updated
2026-01-08
Name servers
  • ns65.domaincontrol.com
  • ns66.domaincontrol.com

DNS records live

NS
  • ns65.domaincontrol.com
  • ns66.domaincontrol.com
MX
  • 0 zaffra-com.mail.protection.outlook.com
TXT
  • v=verifydomain MS=4429081

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6YANgP1h3w4YnT1dVJqlOMgOgO4646B5i9V59RdCwN8G12PZAQG2ojoSPfm6zVakbtdthyPWwE+N5TVzcO…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0xdi9ISmEn43b35RJpyHaL6HNAYpgL0Yp2tb1BlyAm9R2DXMcn3vM7jMQly95heoi7KGX9Ntkb1eld6kRo…
selectors probed

Certificate (current)

R13
from 2026-05-04 to 2026-08-02
Expires in 74 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://zaffra.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=(), speaker-selection=(), conversion-measurement=(), focus-without-user-activation=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), sync-script=(), trust-token-redemption=(), window-placement=(), vertical-scroll=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' blob: data: www.googletagmanager.com www.google-analytics.com www.google.com www.google.nl analytics.google.com ajax.googleapis.com *.google-analytics.com *.g.doubleclick.net www.youtube.com *.prismic.io www.gravatar.com dpdk.com form.typeform.com *.cookiebot.com *.googlesyndication.com api.mapbox.com js.hs-scripts.com *.hsforms.net *.hsforms.com *.hs-scripts.com *.hs-analytics.net *.hscollectedforms.net *.hs-banner.com *.hubspot.com
strict-transport-security
max-age=63072000; includeSubDomains; preload

Linked from (1)