PUBLIC DOSSIER / DATED OBSERVATION

hursad.org

Scope completed

Dossier overview

Summary

11/ 12

Documented angles

Reading coverage, not a security grade.

9 public observations are documented in this dossier.

7 structuring public dependencies are visible.

No useful change is retained since the previous reading.

4 points still require confirmation or cannot be observed from outside.

Distinct evidence
67
Retained signals
3
Identified products
5

General information

Domain name
hursad.org
Reading state
Scope completed
Registered on
2013-11-18 10:29 UTC
Registrar
Çizgi Telekomunikasyon A.Ş.
Stated expiration
2026-11-18 10:29 UTC
Registry outcome
Observed
View information and sources →

Domain registration, not the website or company creation date.

Documentary footprint

S / SCANAPSE
hursad.org2026-09-29 17:03 UTC

Hursad

Angles
11/12
Evidence
67
Signals
3

Preview of the retained dossier, not a screenshot of the target.

View observed content →

Estimated countries of observed IPs

View details →
FijiTanzaniaWestern SaharaCanadaUnited StatesKazakhstanUzbekistanPapua New GuineaIndonesiaArgentinaChileDemocratic Republic of the CongoSomaliaKenyaSudanChadHaitiDominican RepublicRussiaBahamasFalkland IslandsNorwayGreenlandFrench Southern TerritoriesTimor LesteSouth AfricaLesothoMexicoUruguayBrazilBoliviaPeruColombiaPanamaCosta RicaNicaraguaHondurasEl SalvadorGuatemalaBelizeVenezuelaGuyanaSurinameFranceEcuadorPuerto RicoJamaicaCubaZimbabweBotswanaNamibiaSenegalMaliMauritaniaBeninNigerNigeriaCameroonTogoGhanaIvory CoastGuineaGuinea-BissauLiberiaSierra LeoneBurkina FasoCentral African RepublicRepublic of the CongoGabonEquatorial GuineaZambiaMalawiMozambiqueEswatiniAngolaBurundiIsraelLebanonMadagascarPalestinian TerritoryGambiaTunisiaAlgeriaJordanUnited Arab EmiratesQatarKuwaitIraqOmanVanuatuCambodiaThailandLaosMyanmarVietnamNorth KoreaSouth KoreaMongoliaIndiaBangladeshBhutanNepalPakistanAfghanistanTajikistanKyrgyzstanTurkmenistanIranSyriaArmeniaSwedenBelarusUkrainePolandAustriaHungaryMoldovaRomaniaLithuaniaLatviaEstoniaGermanyBulgariaGreeceTurkeyAlbaniaCroatiaSwitzerlandLuxembourgBelgiumThe NetherlandsPortugalSpainIrelandNew CaledoniaSolomon IslandsNew ZealandAustraliaSri LankaChinaTaiwanItalyDenmarkUnited KingdomIcelandAzerbaijanGeorgiaPhilippinesMalaysiaBruneiSloveniaFinlandSlovakiaCzechiaEritreaJapanParaguayYemenSaudi ArabiaAntarcticaCyprusCyprusMoroccoEgyptLibyaEthiopiaDjiboutiSomaliaUgandaRwandaBosnia and HerzegovinaNorth MacedoniaSerbiaMontenegroKosovoTrinidad and TobagoSouth Sudan

Estimate from the local dataset recorded with this measurement. This country locates neither the organisation nor its data; a proxy or anycast network may represent several points of presence.

1 recorded IP address(es) / 1 country estimate(s) available

  • 185.111.234.19TurkeyConnected IP

Country-level estimates do not locate an organisation or its stored data.IP Geolocation by DB-IP · 2026-09 · CC BY 4.0. Natural Earth

Key signals

Inspect →

No summary signal retained. This does not mean “no risk”.

Each finding remains linked to its scope, evidence and limitations.

Visible relationships

Explore all →
hursad.orgus.dnsenable.comdepends on provider
hursad.orgus.dnsenable.comuses nameserver
hursad.orgtr.dnsenable.comdepends on provider
hursad.orgmx01.hursad.orguses mail exchanger
The twelve reading angles

02 / IDENTITY & CONTEXT

The domain, without assumptions

Domain registration

Observed host
hursad.org
Registry query domain
hursad.org
Registered on
2013-11-18 10:29 UTC
Registrar
Çizgi Telekomunikasyon A.Ş.
Stated expiration
2026-11-18 10:29 UTC
Collection outcome
Observed
Read RDAP source ↗

2026-09-29 17:03 UTC

Registration is neither the founding of a company nor the first launch of a website. Personal contact details are not reproduced.

Estimated countries of observed IPs

FijiTanzaniaWestern SaharaCanadaUnited StatesKazakhstanUzbekistanPapua New GuineaIndonesiaArgentinaChileDemocratic Republic of the CongoSomaliaKenyaSudanChadHaitiDominican RepublicRussiaBahamasFalkland IslandsNorwayGreenlandFrench Southern TerritoriesTimor LesteSouth AfricaLesothoMexicoUruguayBrazilBoliviaPeruColombiaPanamaCosta RicaNicaraguaHondurasEl SalvadorGuatemalaBelizeVenezuelaGuyanaSurinameFranceEcuadorPuerto RicoJamaicaCubaZimbabweBotswanaNamibiaSenegalMaliMauritaniaBeninNigerNigeriaCameroonTogoGhanaIvory CoastGuineaGuinea-BissauLiberiaSierra LeoneBurkina FasoCentral African RepublicRepublic of the CongoGabonEquatorial GuineaZambiaMalawiMozambiqueEswatiniAngolaBurundiIsraelLebanonMadagascarPalestinian TerritoryGambiaTunisiaAlgeriaJordanUnited Arab EmiratesQatarKuwaitIraqOmanVanuatuCambodiaThailandLaosMyanmarVietnamNorth KoreaSouth KoreaMongoliaIndiaBangladeshBhutanNepalPakistanAfghanistanTajikistanKyrgyzstanTurkmenistanIranSyriaArmeniaSwedenBelarusUkrainePolandAustriaHungaryMoldovaRomaniaLithuaniaLatviaEstoniaGermanyBulgariaGreeceTurkeyAlbaniaCroatiaSwitzerlandLuxembourgBelgiumThe NetherlandsPortugalSpainIrelandNew CaledoniaSolomon IslandsNew ZealandAustraliaSri LankaChinaTaiwanItalyDenmarkUnited KingdomIcelandAzerbaijanGeorgiaPhilippinesMalaysiaBruneiSloveniaFinlandSlovakiaCzechiaEritreaJapanParaguayYemenSaudi ArabiaAntarcticaCyprusCyprusMoroccoEgyptLibyaEthiopiaDjiboutiSomaliaUgandaRwandaBosnia and HerzegovinaNorth MacedoniaSerbiaMontenegroKosovoTrinidad and TobagoSouth Sudan

Estimate from the local dataset recorded with this measurement. This country locates neither the organisation nor its data; a proxy or anycast network may represent several points of presence.

1 recorded IP address(es) / 1 country estimate(s) available

  • 185.111.234.19TurkeyConnected IP

Country-level estimates do not locate an organisation or its stored data.IP Geolocation by DB-IP · 2026-09 · CC BY 4.0. Natural Earth

Context and documentary references

Estimated IP countries and a provider’s context do not establish applicable jurisdiction or compliance.

Regulatory context to determine

The available public evidence does not establish a sufficiently reliable jurisdiction for automatic legal contextualisation.

Applicability requires review; not a legal determination.

Technical hosting, IP addresses, ASNs and CDN locations do not establish the applicable legal jurisdiction by themselves.

The applicable jurisdiction requires additional public or organisational evidence.

03 / TECHNICAL CLUES

Visible technologies and services

A resource or response header is a public clue, not a server inspection.

LiteSpeed

Technology fingerprint

HTTP Server header

2026-09-29 17:03 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

PHP/7.2.34, PleskLin

Technology fingerprint

X-Powered-By header

2026-09-29 17:03 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

Bootstrap

Technology fingerprint

Bootstrap asset filename

2026-09-29 17:03 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

PHP

Technology fingerprint

PHP session cookie

2026-09-29 17:03 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

Google Fonts

Referenced service

fonts.googleapis.com/css

2026-09-29 17:03 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

04 / WHAT CONNECTS

Visible domain relationships

Technical relationships, not ownership links or assumed partnerships.

hursad.orgCloudflare

depends on provider

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"d4a2ccc52a683d7e64d0add116f92b48251361e28d75cbd263c253ba4bde0c8a","subject":"hursad.org","predicate":"depends_on_provider","object":"Cloudflare","state":"observed","evidence_ids":["48f040054673a87929263d7803f2e792622b9f1b701a428b2bea20eb602d4bce"],"first_seen_at":"2026-09-29T17:03:05+00:00","last_seen_at":"2026-09-29T17:03:05+00:00"}
hursad.org185.111.234.19

resolves to

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"eb18125bbb8094cde0ec9da83b28cd3225f0f8eec8c803ba52f7f73d1a46fd70","subject":"hursad.org","predicate":"resolves_to","object":"185.111.234.19","state":"observed","evidence_ids":["e1563cdbe01e915b5e808c5ea6552e7c4f112def0168975fe643be72b3a20f2e"],"first_seen_at":"2026-09-29T17:03:05+00:00","last_seen_at":"2026-09-29T17:03:05+00:00"}
hursad.orgeu.dnsenable.com

uses nameserver

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"f8da1b08812630ef491166f898d7f2620542abb67e166b64f09a692ac13a6a42","subject":"hursad.org","predicate":"uses_nameserver","object":"eu.dnsenable.com","state":"observed","evidence_ids":["d6c1e92d1415eb39e3905c93aa99cf849f0d77106fb4d09385d29ede2e156220"],"first_seen_at":"2026-09-29T17:03:05+00:00","last_seen_at":"2026-09-29T17:03:05+00:00"}
hursad.orgmx01.hursad.org

depends on provider

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"fdf4b1399c74ee98fcc86619134be207150b4de6419b87e34e54fb8bd5acdf1a","subject":"hursad.org","predicate":"depends_on_provider","object":"mx01.hursad.org","state":"observed","evidence_ids":["b581ff9c942c7c2c177a98f74ac158966aa5d9dfcf1dcc710af9dbce18c231ee"],"first_seen_at":"2026-09-29T17:03:05+00:00","last_seen_at":"2026-09-29T17:03:05+00:00"}

05 / POINTS TO EXAMINE

Signals, context and limitations

No summary signal retained. This is not a finding of no risk.

All retained signals (3)

Effective data location cannot be determined

A provider headquarters, an IP address, or a CDN is not proof of data location.

Visible provider dependencies

Provider visibility does not describe contracts, subprocessors, or actual processing location.

Origin hosting cannot be determined

Edge presence must not be treated as origin hosting.

Retained technical findings and limitations

Network reachability

DNS and email

Single DNS provider The name servers appear to belong to the same provider domain.

["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com"]

DMARC not detected No DMARC policy was observed for the domain.

CAA not published No authorized certificate authority is declared in DNS.

DNSSEC not asserted The autonomous engine does not use a third-party resolver and therefore does not infer DNSSEC validation.

{"status":"not_tested","reason":"No external validating resolver is used; cryptographic validation is intentionally not inferred."}

Email trust

DMARC missing No DMARC policy was observed for a domain that receives email.

TLS reporting not declared No TLS-RPT record was observed.

MTA-STS not declared The MTA-STS version DNS signal was not observed.

Single MX relay Only one mail relay was observed.

[{"host":"mx01.hursad.org","priority":10}]

TLS transport

Security headers

Content-Security-Policy missing The browser receives no explicit resource loading policy.

nosniff missing The browser may try to interpret a content type differently from the declared type.

Anti-framing protection missing The page may potentially be embedded in a hostile iframe.

Referrer-Policy missing Referrer URLs may be transmitted with uncontrolled granularity.

Permissions-Policy missing Unused browser capabilities are not explicitly disabled.

COOP isolation missing The browsing context is not isolated from cross-origin windows.

CORP missing The cross-origin resource sharing policy is not explicit.

COEP missing Embedded resource isolation is not enabled.

Runtime exposed X-Powered-By discloses unnecessary technical information.

php/7.2.34, plesklin

Third-party resource control

Third-party scripts without declared integrity External scripts are loaded without an observable SRI hash. Some dynamic resources do not support SRI.

["s7.addthis.com","cdnjs.cloudflare.com"]

Inline event handlers Inline JavaScript attributes make a strict CSP harder to maintain.

35

External links without explicit isolation Links opened in a new tab do not declare rel=noopener or noreferrer.

1

Dependencies

Highly dependent ecosystem The public document reveals several third-party providers or services.

["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com","Google","s7.addthis.com","Cloudflare","mx01.hursad.org"]

Unattributed providers Some external hosts do not yet match the provider catalog.

["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com","s7.addthis.com","mx01.hursad.org"]

Privacy

Cookie without Secure A cookie received over HTTPS does not explicitly require encrypted transport.

PHPSESSID

Sensitive cookie accessible to JavaScript The cookie name suggests session or authentication use without HttpOnly.

PHPSESSID

SameSite not explicit The cookie does not declare a SameSite strategy.

PHPSESSID

Technology footprint

Technical versions exposed Headers or metadata reveal precise software versions.

["PHP/7.2.34, PleskLin"]

Estimated sovereignty

Dependencies outside Europe Providers legally associated with countries outside Europe appear in the observed scope.

["Google","Cloudflare"]

Jurisdictions to qualify The jurisdiction of some external hosts could not be reliably attributed.

["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com","s7.addthis.com","mx01.hursad.org"]

Resilience

Concentrated DNS All observed name servers appear to depend on the same operator domain.

["eu.dnsenable.com","tr.dnsenable.com","us.dnsenable.com"]

Single address observed Public DNS returns a single address at scan time.

["185.111.234.19"]

Transparency

security.txt missing or incomplete No usable /.well-known/security.txt file with a Contact field was observed.

404

Privacy information not found No obvious link to a privacy policy was identified on the page.

Legal notice not found No obvious legal link was identified in the public document.

origin_host

data_location

Full structured details remain in the JSON report. Missing information is not reconstructed.

06 / THE INSPECTED PAGE

Declared public content

Observed title
Hursad
Description
Hursad
Declared structured-data types
Not documented

The target’s JavaScript is not executed. A website declaration does not certify its identity.

07 / REVIEWED REFERENCES

Reviewed external references

Sources reviewed in administration, not an exhaustive Internet search. They do not modify the historical measurement.

No reviewed external reference recorded.

08 / PUBLIC RESOURCES

Documents and references

09 / TIME CHANGES THE READING

The domain timeline

Initial reference point for this reading.

  1. Displayed reading

Open dedicated history →

10 / KEEP THE READING VERIFIABLE

Evidence, not a score

The twelve angles organise the same evidence. An evidence item reused several times does not become several measurements.

Domain identityObserved

What is being observed and which public markers identify it?

Observed : Technical finding : Signal importance : medium / Observed : Dns nameserver : tr.dnsenable.com

Technical finding Observed

Signal importance : medium

dns

Dns nameserver Observed

tr.dnsenable.com

dns

Mail exchanger Observed

mx01.hursad.org

dns

Dns nameserver Observed

us.dnsenable.com

dns

Dns nameserver Observed

eu.dnsenable.com

dns

Dns address Observed

185.111.234.19

dns

InfrastructureReview needed

Which public infrastructures appear to serve the service?

Observed : Provider dependency : Cloudflare / Undetermined : Origin host : Value not available

Provider dependency Observed

Cloudflare

provider_observed_once

Origin host Undetermined

Value not available

public_edge_does_not_reveal_origin

Provider dependency Observed

tr.dnsenable.com

provider_observed_once

Provider dependency Observed

mx01.hursad.org

provider_observed_once

Data location Undetermined

Value not available

provider_metadata_does_not_prove_processing_location

Provider dependency Observed

Google

provider_observed_once

Encryption and transportObserved

How are public exchanges protected and presented?

Observed : Tls issuer : C = US, O = SSL Corp, CN = TrustSafe TLS RSA SubCA 2 / Not tested : Post-quantum TLS negotiation : No measurement performed

Tls issuer Observed

C = US, O = SSL Corp, CN = TrustSafe TLS RSA SubCA 2

certificate_observed

Post-quantum TLS negotiation Not tested

No measurement performed

client_capability_unavailable

Tls valid to Observed

2027-03-06T18:53:46+00:00

tls

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Signal importance : medium

headers

Mail and trustObserved

Which mail protections and policies are publicly observable?

Observed : SPF policy : hardfail / Observed : Technical finding : Signal importance : medium

SPF policy Observed

hardfail

mail_policy_observed

Technical finding Observed

Signal importance : medium

dns

Dns nameserver Observed

tr.dnsenable.com

dns

Mail policy flag Observed

No

mail_trust

Mail exchanger Observed

mx01.hursad.org

dns

Technical finding Observed

Evidence : Host : mx01.hursad.org ; Priority : 10 ; Signal importance : low

mail_trust

DNS and governanceObserved

Which public DNS controls are visible and what remains undetermined?

Observed : Technical finding : Signal importance : medium / Observed : Dns nameserver : tr.dnsenable.com

Technical finding Observed

Signal importance : medium

dns

Dns nameserver Observed

tr.dnsenable.com

dns

Mail policy flag Observed

No

mail_trust

Mail exchanger Observed

mx01.hursad.org

dns

Technical finding Observed

Evidence : Host : mx01.hursad.org ; Priority : 10 ; Signal importance : low

mail_trust

Dns nameserver Observed

us.dnsenable.com

dns

External dependenciesReview needed

Which external domains, providers or resources does the site visibly depend on?

Observed : Provider dependency : Cloudflare / Observed : Provider dependency : tr.dnsenable.com

Provider dependency Observed

Cloudflare

provider_observed_once

Provider dependency Observed

tr.dnsenable.com

provider_observed_once

Provider dependency Observed

mx01.hursad.org

provider_observed_once

Provider dependency Observed

Google

provider_observed_once

Provider dependency Observed

us.dnsenable.com

provider_observed_once

Provider dependency Observed

s7.addthis.com

provider_observed_once

Observable technologiesObserved

Which technologies can reasonably be inferred from public traces?

Observed : Technology : Name : PHP ; Version exposed : No / Observed : Technical finding : Signal importance : low

Technology Observed

Name : PHP ; Version exposed : No

technology

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Signal importance : medium

headers

Technology Observed

Name : LiteSpeed ; Version exposed : No

technology

Technical finding Observed

Signal importance : low

headers

Public exposureObserved

Which elements, endpoints or artefacts are publicly exposed?

To confirm : Canary statement detected : No / Observed : Technical finding : Signal importance : medium

Canary statement detected To confirm

No

no_known_passive_signature_observed

Technical finding Observed

Signal importance : medium

dns

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Evidence : eu.dnsenable.com ; mx01.hursad.org ; s7.addthis.com ; tr.dnsenable.com ; us.dnsenable.com ; Signal importance : medium

dependencies

Technical finding Observed

Evidence : Cloudflare ; Google ; eu.dnsenable.com ; mx01.hursad.org ; s7.addthis.com ; tr.dnsenable.com ; us.dnsenable.com ; Signal importance : medium

dependencies

Documentary trustObserved

Which public documents and transparency mechanisms are present?

Observed : Technical finding : Signal importance : medium / Observed : Technical finding : Signal importance : low

Technical finding Observed

Signal importance : medium

dns

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Signal importance : low

headers

Technical finding Observed

Evidence : eu.dnsenable.com ; mx01.hursad.org ; s7.addthis.com ; tr.dnsenable.com ; us.dnsenable.com ; Signal importance : medium

dependencies

Technical finding Observed

Evidence : Cloudflare ; Google ; eu.dnsenable.com ; mx01.hursad.org ; s7.addthis.com ; tr.dnsenable.com ; us.dnsenable.com ; Signal importance : medium

dependencies

Technical finding Observed

Evidence : PHPSESSID ; Signal importance : high

privacy

Security signalsObserved

Which protections or situations deserve particular attention?

To confirm : Canary statement detected : No / Not tested : Post-quantum TLS negotiation : No measurement performed

Canary statement detected To confirm

No

no_known_passive_signature_observed

Post-quantum TLS negotiation Not tested

No measurement performed

client_capability_unavailable

Tls valid to Observed

2027-03-06T18:53:46+00:00

tls

Technical finding Observed

Signal importance : medium

dns

Technical finding Observed

Signal importance : low

headers

Dns nameserver Observed

tr.dnsenable.com

dns

Evolution over timeUndetermined

What appeared, disappeared, changed or remained stable since earlier scans?

The available evidence does not yet describe this pillar

Evidence and traceabilityReview needed

Which evidence, methods, dates and limitations support the displayed conclusions?

Observed : Tls valid to : 2027-03-06T18:53:46+00:00 / Observed : Dnssec evidence : Chain consistency : Reason : insufficient_record_evidence ; State : untested ; Dnskey : Query supported : No ; State : untested ; Ds : Query supported : No ; State : untested ; Validation : Reason : no_validating_resolver ; State : untested

Tls valid to Observed

2027-03-06T18:53:46+00:00

tls

Dnssec evidence Observed

Chain consistency : Reason : insufficient_record_evidence ; State : untested ; Dnskey : Query supported : No ; State : untested ; Ds : Query supported : No ; State : untested ; Validation : Reason : no_validating_resolver ; State : untested

dnssec_depth

Technology Observed

Name : PHP ; Version exposed : No

technology

Technical finding Observed

Signal importance : medium

dns

Technical finding Observed

Signal importance : low

headers

Dns nameserver Observed

tr.dnsenable.com

dns

Evidence record

The filter changes the display. Exports retain all evidence.

tls_valid_toe2c2bacb65f1803c44
Observed value
2027-03-06T18:53:46+00:00
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
tls
Method
TLS handshake and public certificate inspection
Limitations
Strong TLS does not prove application security or origin-server security behind a CDN or reverse proxy.
dnssec_evidencec04f76d012a8d87b59
Observed value
{"chain_consistency":{"reason":"insufficient_record_evidence","state":"untested"},"dnskey":{"query_supported":false,"records":[],"state":"untested"},"ds":{"query_supported":false,"records":[],"state":"untested"},"validation":{"reason":"no_validating_resolver","state":"untested"}}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dnssec_depth
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
technology79da05223f6c9d7b78
Observed value
{"name":"PHP","version":"","version_exposed":false}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
technology
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
module_finding34e37167b83e840f0c
Observed value
{"evidence":null,"severity":"medium"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
module_finding2a906ddfb80d353760
Observed value
{"evidence":null,"severity":"low"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
headers
Method
HTTP response-header inspection
Limitations
A header being present does not prove it is optimal or that the application has no vulnerabilities.
dns_nameserver83de4257e38abae0ab
Observed value
tr.dnsenable.com
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
module_findinga35a74118b2269899e
Observed value
{"evidence":null,"severity":"low"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
headers
Method
HTTP response-header inspection
Limitations
A header being present does not prove it is optimal or that the application has no vulnerabilities.
module_finding11f409f888071d1e74
Observed value
{"evidence":["eu.dnsenable.com","mx01.hursad.org","s7.addthis.com","tr.dnsenable.com","us.dnsenable.com"],"severity":"medium"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dependencies
Method
Public HTML/resource dependency extraction and provider matching
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
mail_policy_flag8f80a14cdb275c1183
Observed value
false
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
mail_trust
Method
Public DNS and policy endpoint inspection
Limitations
They do not prove actual deliverability, every recipient’s behavior, or the absence of phishing.
module_finding8067cf05345f0e2e09
Observed value
{"evidence":["Cloudflare","Google","eu.dnsenable.com","mx01.hursad.org","s7.addthis.com","tr.dnsenable.com","us.dnsenable.com"],"severity":"medium"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dependencies
Method
Public HTML/resource dependency extraction and provider matching
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
canary_signal8fcf5f129ff0019913
Observed value
{"matches":[],"reason":"no_known_passive_signature_observed","signature_version":"2026.09.1","state":"not_observed"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
canary_passive
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
module_findingaa0c0ca39d90828185
Observed value
{"evidence":"PHPSESSID","severity":"high"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
privacy
Method
Visible cookies and tracker signatures on the public response
Limitations
This observation is never a GDPR audit and does not reveal every purpose or internal processing activity.
dependency_provider48f040054673a87929
Observed value
{"critical":false,"hosts":["cdnjs.cloudflare.com"],"id":"cloudflare","known":true,"name":"Cloudflare","observation_count":1,"services":["cdn","security"],"tracker":false}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dependencies
Method
Public HTML/resource dependency extraction and provider matching
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
mail_exchanger5c6eadac0d5fe49c77
Observed value
mx01.hursad.org
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
module_finding2e30a75e97255a7da2
Observed value
{"evidence":[{"host":"mx01.hursad.org","priority":10}],"severity":"low"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
mail_trust
Method
Public DNS and policy endpoint inspection
Limitations
They do not prove actual deliverability, every recipient’s behavior, or the absence of phishing.
module_finding50064ba9522a5ab5dc
Observed value
{"evidence":["185.111.234.19"],"severity":"info"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
resilience
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
dns_nameserver2d329a6eeb7d356d3a
Observed value
us.dnsenable.com
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
dependency_providerb581ff9c942c7c2c17
Observed value
{"critical":false,"hosts":["mx01.hursad.org"],"id":"host-3a6f5743a8f4","known":false,"name":"mx01.hursad.org","observation_count":1,"services":["unknown"],"tracker":false}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
dependencies
Method
Public HTML/resource dependency extraction and provider matching
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
modern_transport_evidence734d3de76ea9dd622c
Observed value
{"alpn":{"state":"untested","value":""},"certificate":{"cipher":"","issuer":"C = US, O = SSL Corp, CN = TrustSafe TLS RSA SubCA 2","protocol":"","san_count":0,"state":"observed","valid_from":"2026-08-20T18:53:46+00:00","valid_to":"2027-03-06T18:53:46+00:00"},"http2":{"negotiated":"2","state":"observed"},"http3_advertised":{"alt_svc":"","state":"not_observed"},"ipv4":{"addresses":["185.111.234.19"],"state":"observed"},"ipv6":{"addresses":[],"state":"not_observed"}}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
modern_transport
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
module_finding508f86344a20fc5ee7
Observed value
{"evidence":null,"severity":"low"}
Source
release_fallback
Date
2026-09-29T17:03:05+00:00
Collector
mail_trust
Method
Public DNS and policy endpoint inspection
Limitations
They do not prove actual deliverability, every recipient’s behavior, or the absence of phishing.
An explainable reading, not artificial certainty.

Public access, collection budgets and available sources limit this dossier. A hash or signature is not certification of its conclusions.

Report an error or request clarification ↗