No summary signal retained. This is not a finding of no risk.
Retained technical findings and limitations
Network reachability
DNS and email
Single DNS provider The name servers appear to belong to the same provider domain.
["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com"]
DMARC not detected No DMARC policy was observed for the domain.
CAA not published No authorized certificate authority is declared in DNS.
DNSSEC not asserted The autonomous engine does not use a third-party resolver and therefore does not infer DNSSEC validation.
{"status":"not_tested","reason":"No external validating resolver is used; cryptographic validation is intentionally not inferred."}Email trust
DMARC missing No DMARC policy was observed for a domain that receives email.
TLS reporting not declared No TLS-RPT record was observed.
MTA-STS not declared The MTA-STS version DNS signal was not observed.
Single MX relay Only one mail relay was observed.
[{"host":"mx01.hursad.org","priority":10}]TLS transport
Security headers
Content-Security-Policy missing The browser receives no explicit resource loading policy.
nosniff missing The browser may try to interpret a content type differently from the declared type.
Anti-framing protection missing The page may potentially be embedded in a hostile iframe.
Referrer-Policy missing Referrer URLs may be transmitted with uncontrolled granularity.
Permissions-Policy missing Unused browser capabilities are not explicitly disabled.
COOP isolation missing The browsing context is not isolated from cross-origin windows.
CORP missing The cross-origin resource sharing policy is not explicit.
COEP missing Embedded resource isolation is not enabled.
Runtime exposed X-Powered-By discloses unnecessary technical information.
php/7.2.34, plesklin
Third-party resource control
Third-party scripts without declared integrity External scripts are loaded without an observable SRI hash. Some dynamic resources do not support SRI.
["s7.addthis.com","cdnjs.cloudflare.com"]
Inline event handlers Inline JavaScript attributes make a strict CSP harder to maintain.
35
External links without explicit isolation Links opened in a new tab do not declare rel=noopener or noreferrer.
1
Dependencies
Highly dependent ecosystem The public document reveals several third-party providers or services.
["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com","Google","s7.addthis.com","Cloudflare","mx01.hursad.org"]
Unattributed providers Some external hosts do not yet match the provider catalog.
["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com","s7.addthis.com","mx01.hursad.org"]
Privacy
Cookie without Secure A cookie received over HTTPS does not explicitly require encrypted transport.
PHPSESSID
Sensitive cookie accessible to JavaScript The cookie name suggests session or authentication use without HttpOnly.
PHPSESSID
SameSite not explicit The cookie does not declare a SameSite strategy.
PHPSESSID
Technology footprint
Technical versions exposed Headers or metadata reveal precise software versions.
["PHP/7.2.34, PleskLin"]
Estimated sovereignty
Dependencies outside Europe Providers legally associated with countries outside Europe appear in the observed scope.
["Google","Cloudflare"]
Jurisdictions to qualify The jurisdiction of some external hosts could not be reliably attributed.
["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com","s7.addthis.com","mx01.hursad.org"]
Resilience
Concentrated DNS All observed name servers appear to depend on the same operator domain.
["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com"]
Single address observed Public DNS returns a single address at scan time.
["185.111.234.19"]
Transparency
security.txt missing or incomplete No usable /.well-known/security.txt file with a Contact field was observed.
404
Privacy information not found No obvious link to a privacy policy was identified on the page.
Legal notice not found No obvious legal link was identified in the public document.
origin_hostdata_locationFull structured details remain in the JSON report. Missing information is not reconstructed.