Retained technical findings and limitations
Network reachability
Slow response Retrieval took more than two seconds.
3327.08 ms
DNS and email
Single DNS provider The name servers appear to belong to the same provider domain.
["nancy.ns.cloudflare.com","boyd.ns.cloudflare.com"]
DMARC not detected No DMARC policy was observed for the domain.
CAA not published No authorized certificate authority is declared in DNS.
DNSSEC not asserted The autonomous engine does not use a third-party resolver and therefore does not infer DNSSEC validation.
{"status":"not_tested","reason":"No external validating resolver is used; cryptographic validation is intentionally not inferred."}Email trust
DMARC missing No DMARC policy was observed for a domain that receives email.
TLS reporting not declared No TLS-RPT record was observed.
MTA-STS not declared The MTA-STS version DNS signal was not observed.
TLS transport
Security headers
Content-Security-Policy missing The browser receives no explicit resource loading policy.
Permissions-Policy missing Unused browser capabilities are not explicitly disabled.
COOP isolation missing The browsing context is not isolated from cross-origin windows.
CORP missing The cross-origin resource sharing policy is not explicit.
COEP missing Embedded resource isolation is not enabled.
Third-party resource control
Third-party scripts without declared integrity External scripts are loaded without an observable SRI hash. Some dynamic resources do not support SRI.
["www.googletagmanager.com","cdn.jsdelivr.net"]
External links without explicit isolation Links opened in a new tab do not declare rel=noopener or noreferrer.
1
Dependencies
Highly dependent ecosystem The public document reveals several third-party providers or services.
["Cloudflare","cdn.jsdelivr.net","Google","vade-mx-fr01.hornetsecurity.com","vade-mx-fr02.hornetsecurity.com","vade-mx-eu-fallback02.hornetsecurity.com","vade-mx-eu-fallback01.hornetsecurity.com"]
Unattributed providers Some external hosts do not yet match the provider catalog.
["cdn.jsdelivr.net","vade-mx-fr01.hornetsecurity.com","vade-mx-fr02.hornetsecurity.com","vade-mx-eu-fallback02.hornetsecurity.com","vade-mx-eu-fallback01.hornetsecurity.com"]
Privacy
Trackers or analytics services detected Providers known for analytics, advertising, or behavioral measurement appear in public resources.
["Google"]
Technology footprint
Estimated sovereignty
Dependencies outside Europe Providers legally associated with countries outside Europe appear in the observed scope.
["Cloudflare","Google"]
Jurisdictions to qualify The jurisdiction of some external hosts could not be reliably attributed.
["cdn.jsdelivr.net","vade-mx-fr01.hornetsecurity.com","vade-mx-fr02.hornetsecurity.com","vade-mx-eu-fallback02.hornetsecurity.com","vade-mx-eu-fallback01.hornetsecurity.com"]
Resilience
Concentrated DNS All observed name servers appear to depend on the same operator domain.
["nancy.ns.cloudflare.com","boyd.ns.cloudflare.com"]
Single address observed Public DNS returns a single address at scan time.
["5.250.177.164"]
Transparency
security.txt missing or incomplete No usable /.well-known/security.txt file with a Contact field was observed.
404
Privacy information not found No obvious link to a privacy policy was identified on the page.
origin_hostdata_locationFull structured details remain in the JSON report. Missing information is not reconstructed.