DNS and email
Insufficient DNS redundancy Fewer than two name servers were observed.
CAA not published No authorized certificate authority is declared in DNS.
DNSSEC not asserted The autonomous engine does not use a third-party resolver and therefore does not infer DNSSEC validation.
{"status":"not_tested","reason":"No external validating resolver is used; cryptographic validation is intentionally not inferred."}Security headers
CSP allows unsafe-inline The policy permits inline execution or styling without cryptographic proof.
img-src 'self' impots.gouv.fr *.impots.gouv.fr *.france-services.gouv.fr *.openstreetmap.org *.w3.org *.basemaps.cartocdn.com data: *.w3.org *.data.economie.gouv.fr *.basemaps.cartocdn.com; script-src 'self' impots.gouv.fr *.impots.gouv.fr 'unsafe-eval' 'unsafe-inline'; style-src 'unsafe-eval' 'unsafe-inline' *.impots.gouv.fr 'self';frame-ancestors 'self'; worker-src blob:
CSP allows unsafe-eval The policy permits risky code evaluation APIs.
img-src 'self' impots.gouv.fr *.impots.gouv.fr *.france-services.gouv.fr *.openstreetmap.org *.w3.org *.basemaps.cartocdn.com data: *.w3.org *.data.economie.gouv.fr *.basemaps.cartocdn.com; script-src 'self' impots.gouv.fr *.impots.gouv.fr 'unsafe-eval' 'unsafe-inline'; style-src 'unsafe-eval' 'unsafe-inline' *.impots.gouv.fr 'self';frame-ancestors 'self'; worker-src blob:
nosniff missing The browser may try to interpret a content type differently from the declared type.
Referrer-Policy missing Referrer URLs may be transmitted with uncontrolled granularity.
Permissions-Policy missing Unused browser capabilities are not explicitly disabled.
COOP isolation missing The browsing context is not isolated from cross-origin windows.
CORP missing The cross-origin resource sharing policy is not explicit.
COEP missing Embedded resource isolation is not enabled.
Full structured details remain in the JSON report. Missing information is not reconstructed.