PUBLIC DOSSIER / DATED OBSERVATION

jcconfection.fr

Scope completed

Dossier overview

Summary

11/ 12

Documented angles

Reading coverage, not a security grade.

9 public observations are documented in this dossier.

7 structuring public dependencies are visible.

No useful change is retained since the previous reading.

4 points still require confirmation or cannot be observed from outside.

Distinct evidence
60
Retained signals
3
Identified products
3

General information

Domain name
jcconfection.fr
Reading state
Scope completed
Registered on
2024-09-18 06:24 UTC
Registrar
OVH
Stated expiration
2034-09-18 06:24 UTC
Registry outcome
Observed
View information and sources →

Domain registration, not the website or company creation date.

Documentary footprint

S / SCANAPSE
jcconfection.fr2026-09-21 06:20 UTC

JC Confection - Façonnier français de prêt-à-porter haut de gamme

Angles
11/12
Evidence
60
Signals
3

Preview of the retained dossier, not a screenshot of the target.

View observed content →

Estimated countries of observed IPs

View details →
FijiTanzaniaWestern SaharaCanadaUnited StatesKazakhstanUzbekistanPapua New GuineaIndonesiaArgentinaChileDemocratic Republic of the CongoSomaliaKenyaSudanChadHaitiDominican RepublicRussiaBahamasFalkland IslandsNorwayGreenlandFrench Southern TerritoriesTimor LesteSouth AfricaLesothoMexicoUruguayBrazilBoliviaPeruColombiaPanamaCosta RicaNicaraguaHondurasEl SalvadorGuatemalaBelizeVenezuelaGuyanaSurinameFranceEcuadorPuerto RicoJamaicaCubaZimbabweBotswanaNamibiaSenegalMaliMauritaniaBeninNigerNigeriaCameroonTogoGhanaIvory CoastGuineaGuinea-BissauLiberiaSierra LeoneBurkina FasoCentral African RepublicRepublic of the CongoGabonEquatorial GuineaZambiaMalawiMozambiqueEswatiniAngolaBurundiIsraelLebanonMadagascarPalestinian TerritoryGambiaTunisiaAlgeriaJordanUnited Arab EmiratesQatarKuwaitIraqOmanVanuatuCambodiaThailandLaosMyanmarVietnamNorth KoreaSouth KoreaMongoliaIndiaBangladeshBhutanNepalPakistanAfghanistanTajikistanKyrgyzstanTurkmenistanIranSyriaArmeniaSwedenBelarusUkrainePolandAustriaHungaryMoldovaRomaniaLithuaniaLatviaEstoniaGermanyBulgariaGreeceTurkeyAlbaniaCroatiaSwitzerlandLuxembourgBelgiumThe NetherlandsPortugalSpainIrelandNew CaledoniaSolomon IslandsNew ZealandAustraliaSri LankaChinaTaiwanItalyDenmarkUnited KingdomIcelandAzerbaijanGeorgiaPhilippinesMalaysiaBruneiSloveniaFinlandSlovakiaCzechiaEritreaJapanParaguayYemenSaudi ArabiaAntarcticaCyprusCyprusMoroccoEgyptLibyaEthiopiaDjiboutiSomaliaUgandaRwandaBosnia and HerzegovinaNorth MacedoniaSerbiaMontenegroKosovoTrinidad and TobagoSouth Sudan

Estimate from the local dataset recorded with this measurement. This country locates neither the organisation nor its data; a proxy or anycast network may represent several points of presence.

1 recorded IP address(es) / 1 country estimate(s) available

  • 5.250.177.164FranceConnected IP

Country-level estimates do not locate an organisation or its stored data.IP Geolocation by DB-IP · 2026-09 · CC BY 4.0. Natural Earth

Visible relationships

Explore all →
jcconfection.frvade-mx-fr01.hornetsecurity.comuses mail exchanger
jcconfection.frboyd.ns.cloudflare.comuses nameserver
jcconfection.frvade-mx-eu-fallback02.hornetsecurity.comdepends on provider
jcconfection.frvade-mx-fr01.hornetsecurity.comdepends on provider
The twelve reading angles

02 / IDENTITY & CONTEXT

The domain, without assumptions

Domain registration

Observed host
jcconfection.fr
Registry query domain
jcconfection.fr
Registered on
2024-09-18 06:24 UTC
Registrar
OVH
Stated expiration
2034-09-18 06:24 UTC
Collection outcome
Observed
Read RDAP source ↗

2026-09-21 06:20 UTC

Registration is neither the founding of a company nor the first launch of a website. Personal contact details are not reproduced.

Estimated countries of observed IPs

FijiTanzaniaWestern SaharaCanadaUnited StatesKazakhstanUzbekistanPapua New GuineaIndonesiaArgentinaChileDemocratic Republic of the CongoSomaliaKenyaSudanChadHaitiDominican RepublicRussiaBahamasFalkland IslandsNorwayGreenlandFrench Southern TerritoriesTimor LesteSouth AfricaLesothoMexicoUruguayBrazilBoliviaPeruColombiaPanamaCosta RicaNicaraguaHondurasEl SalvadorGuatemalaBelizeVenezuelaGuyanaSurinameFranceEcuadorPuerto RicoJamaicaCubaZimbabweBotswanaNamibiaSenegalMaliMauritaniaBeninNigerNigeriaCameroonTogoGhanaIvory CoastGuineaGuinea-BissauLiberiaSierra LeoneBurkina FasoCentral African RepublicRepublic of the CongoGabonEquatorial GuineaZambiaMalawiMozambiqueEswatiniAngolaBurundiIsraelLebanonMadagascarPalestinian TerritoryGambiaTunisiaAlgeriaJordanUnited Arab EmiratesQatarKuwaitIraqOmanVanuatuCambodiaThailandLaosMyanmarVietnamNorth KoreaSouth KoreaMongoliaIndiaBangladeshBhutanNepalPakistanAfghanistanTajikistanKyrgyzstanTurkmenistanIranSyriaArmeniaSwedenBelarusUkrainePolandAustriaHungaryMoldovaRomaniaLithuaniaLatviaEstoniaGermanyBulgariaGreeceTurkeyAlbaniaCroatiaSwitzerlandLuxembourgBelgiumThe NetherlandsPortugalSpainIrelandNew CaledoniaSolomon IslandsNew ZealandAustraliaSri LankaChinaTaiwanItalyDenmarkUnited KingdomIcelandAzerbaijanGeorgiaPhilippinesMalaysiaBruneiSloveniaFinlandSlovakiaCzechiaEritreaJapanParaguayYemenSaudi ArabiaAntarcticaCyprusCyprusMoroccoEgyptLibyaEthiopiaDjiboutiSomaliaUgandaRwandaBosnia and HerzegovinaNorth MacedoniaSerbiaMontenegroKosovoTrinidad and TobagoSouth Sudan

Estimate from the local dataset recorded with this measurement. This country locates neither the organisation nor its data; a proxy or anycast network may represent several points of presence.

1 recorded IP address(es) / 1 country estimate(s) available

  • 5.250.177.164FranceConnected IP

Country-level estimates do not locate an organisation or its stored data.IP Geolocation by DB-IP · 2026-09 · CC BY 4.0. Natural Earth

Context and documentary references

Estimated IP countries and a provider’s context do not establish applicable jurisdiction or compliance.

GDPR

The observed territorial context links the domain to the European Union. Public privacy signals increase the relevance of this framework without proving internal processing practices.

Applicability requires review; not a legal determination.

Documentary source ↗

NIS2

The directive may apply to some entities depending on sector, size and role. Scanapse does not infer those conditions from a domain alone.

Applicability requires review; not a legal determination.

Documentary source ↗

Cyber Resilience Act

This regulation applies to products with digital elements under specific conditions. A public website alone cannot establish whether an entity or product falls within scope.

Applicability requires review; not a legal determination.

Documentary source ↗

DORA

DORA targets financial entities and certain ICT providers within its scope. Without evidence of sector or status, Scanapse keeps it as context only.

Applicability requires review; not a legal determination.

Documentary source ↗

French Data Protection Act

A French context makes this national data-protection law, complementary to GDPR, potentially relevant to personal-data processing.

Applicability requires review; not a legal determination.

Documentary source ↗

Technical hosting, IP addresses, ASNs and CDN locations do not establish the applicable legal jurisdiction by themselves.

A country-code domain is only a contextual clue and does not prove where the organisation is legally established.

03 / TECHNICAL CLUES

Visible technologies and services

A resource or response header is a public clue, not a server inspection.

Apache

Technology fingerprint

HTTP Server header

2026-09-21 06:20 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

WordPress

Technology fingerprint

WordPress generator or resource path

2026-09-21 06:20 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

Google tag

Referenced service

www.googletagmanager.com/gtag/js

2026-09-21 06:20 UTC

Clue source ↗
Rule and scope

2026.09-v3.1

Does not establish effective execution or a server technology that is not exposed.

04 / WHAT CONNECTS

Visible domain relationships

Technical relationships, not ownership links or assumed partnerships.

jcconfection.frvade-mx-fr01.hornetsecurity.com

uses mail exchanger

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"0d50df27f3bfd0a63861e01385f4cd63024c98d82bada85fda73f5c964060f67","subject":"jcconfection.fr","predicate":"uses_mail_exchanger","object":"vade-mx-fr01.hornetsecurity.com","state":"observed","evidence_ids":["a7178d668e0a046c7774873c2157382f945da232f4b2b66764a5700494963052"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frboyd.ns.cloudflare.com

uses nameserver

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"33380a0ff2355c27bb97e5cc05fae2c907fef661c9b02753e32eca14cad77db4","subject":"jcconfection.fr","predicate":"uses_nameserver","object":"boyd.ns.cloudflare.com","state":"observed","evidence_ids":["85310fc7809cd584275599b39f41b4acad7e6a5c04474515fe3fc2831ae1d66d"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frvade-mx-eu-fallback02.hornetsecurity.com

depends on provider

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"3fd910af58842ee582c9b2810f16c3332368e5412c6d1e2722144eea0cfbedd0","subject":"jcconfection.fr","predicate":"depends_on_provider","object":"vade-mx-eu-fallback02.hornetsecurity.com","state":"observed","evidence_ids":["bd747df18699e6ebb64ba1e0f1c847820200ebb63ba46cfa96e8249150f33725"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frvade-mx-fr01.hornetsecurity.com

depends on provider

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"4ecc2c027545d78f7d5c5817b6e2fe2d435fa6cd947efe607466efced8174e25","subject":"jcconfection.fr","predicate":"depends_on_provider","object":"vade-mx-fr01.hornetsecurity.com","state":"observed","evidence_ids":["faff69959ceac5e98a1291f12cf56f9636ab3a144b0a3d30e9a5a7c068809587"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frvade-mx-eu-fallback01.hornetsecurity.com

uses mail exchanger

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"587a86fca1e766f37a3e6bd673c9cff4feb64879e1d70c2d927c7f5e26130f07","subject":"jcconfection.fr","predicate":"uses_mail_exchanger","object":"vade-mx-eu-fallback01.hornetsecurity.com","state":"observed","evidence_ids":["4b58f7f554c8bd3c50d69128f8ed92f038b59f1973011cd3861f59b17a35169d"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frApache

uses technology

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"58ff197530a0e9c304c1590f7e9266cbff48ad682c9168cc2bc9191c9e61ac49","subject":"jcconfection.fr","predicate":"uses_technology","object":"Apache","state":"observed","evidence_ids":["06c4b3c80ecfa5a42197da9cacc67354bf90045153d8836b37d4d32b7373f79f"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.fr5.250.177.164

resolves to

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"5fcdecc6a35ab808a2092e654b8bb18fd916ce3bf184f3959bdb4d0d33e33fff","subject":"jcconfection.fr","predicate":"resolves_to","object":"5.250.177.164","state":"observed","evidence_ids":["15471723ace686e8c5d010bb0870fba820bfbb52fd7193e8f60e0c3488069e79"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frvade-mx-fr02.hornetsecurity.com

depends on provider

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"716be0bb00632df18c59963b369ecb89efe434e2230761a0c4fbe9c0df665f2a","subject":"jcconfection.fr","predicate":"depends_on_provider","object":"vade-mx-fr02.hornetsecurity.com","state":"observed","evidence_ids":["893b8c734a8a9751c485dc2d6a7d43772d3f823d5d16c83271a81872d217dcd0"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frCloudflare

depends on provider

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"9a3d8612fbf5ff289989a9aa50696c328cd84c84debc46ce7f5671888a0f169b","subject":"jcconfection.fr","predicate":"depends_on_provider","object":"Cloudflare","state":"corroborated","evidence_ids":["fc8b11710b6467536114976d03ffa4d517abc8ebb3964c275fbd21345d504ac1","95478f19272a5b30fa5ce0daadbfcaa3fce8d8aa8bef5e13014304cfe86a88e4","85310fc7809cd584275599b39f41b4acad7e6a5c04474515fe3fc2831ae1d66d"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frcdn.jsdelivr.net

depends on provider

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"a9626e671640cf1ecc867df2b07f64f31b23caca309d4494f6f8dc0b01753b2e","subject":"jcconfection.fr","predicate":"depends_on_provider","object":"cdn.jsdelivr.net","state":"observed","evidence_ids":["a501a884995960a420e1f52137062e586ad56f14661bd0ab8f76bf46679c7566"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frnancy.ns.cloudflare.com

uses nameserver

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"d4f11c98a94daf1aaaecc615b706857752aecdd58d8dfa11d1b68047fe6a6e21","subject":"jcconfection.fr","predicate":"uses_nameserver","object":"nancy.ns.cloudflare.com","state":"observed","evidence_ids":["95478f19272a5b30fa5ce0daadbfcaa3fce8d8aa8bef5e13014304cfe86a88e4"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}
jcconfection.frWordPress

uses technology

Why this connection?

Recorded technical relationship, not a partnership or ownership link.

Retained structured value
{"id":"dae19cc7b7ffb5dd47e98f786346e53885d6e7afdb9ae6975feac5ec14e96a74","subject":"jcconfection.fr","predicate":"uses_technology","object":"WordPress","state":"observed","evidence_ids":["08a4750667eabfc3449273beae313119b5577044ed8edd1875754aae79929786"],"first_seen_at":"2026-09-21T06:20:07+00:00","last_seen_at":"2026-09-21T06:20:07+00:00"}

05 / POINTS TO EXAMINE

Signals, context and limitations

Critical function concentration

Cloudflare is associated with 2 critical function(s) or observations in the visible scope.

This concentration is descriptive. It does not prove a future outage or the absence of failover mechanisms invisible to the scan.

Inspect evidence ↓
All retained signals (3)

Effective data location cannot be determined

A provider headquarters, an IP address, or a CDN is not proof of data location.

Visible provider dependencies

Provider visibility does not describe contracts, subprocessors, or actual processing location.

Origin hosting cannot be determined

Edge presence must not be treated as origin hosting.

Retained technical findings and limitations

Network reachability

Slow response Retrieval took more than two seconds.

3327.08 ms

DNS and email

Single DNS provider The name servers appear to belong to the same provider domain.

["nancy.ns.cloudflare.com","boyd.ns.cloudflare.com"]

DMARC not detected No DMARC policy was observed for the domain.

CAA not published No authorized certificate authority is declared in DNS.

DNSSEC not asserted The autonomous engine does not use a third-party resolver and therefore does not infer DNSSEC validation.

{"status":"not_tested","reason":"No external validating resolver is used; cryptographic validation is intentionally not inferred."}

Email trust

DMARC missing No DMARC policy was observed for a domain that receives email.

TLS reporting not declared No TLS-RPT record was observed.

MTA-STS not declared The MTA-STS version DNS signal was not observed.

TLS transport

Security headers

Content-Security-Policy missing The browser receives no explicit resource loading policy.

Permissions-Policy missing Unused browser capabilities are not explicitly disabled.

COOP isolation missing The browsing context is not isolated from cross-origin windows.

CORP missing The cross-origin resource sharing policy is not explicit.

COEP missing Embedded resource isolation is not enabled.

Third-party resource control

Third-party scripts without declared integrity External scripts are loaded without an observable SRI hash. Some dynamic resources do not support SRI.

["www.googletagmanager.com","cdn.jsdelivr.net"]

External links without explicit isolation Links opened in a new tab do not declare rel=noopener or noreferrer.

1

Dependencies

Highly dependent ecosystem The public document reveals several third-party providers or services.

["Cloudflare","cdn.jsdelivr.net","Google","vade-mx-fr01.hornetsecurity.com","vade-mx-fr02.hornetsecurity.com","vade-mx-eu-fallback02.hornetsecurity.com","vade-mx-eu-fallback01.hornetsecurity.com"]

Unattributed providers Some external hosts do not yet match the provider catalog.

["cdn.jsdelivr.net","vade-mx-fr01.hornetsecurity.com","vade-mx-fr02.hornetsecurity.com","vade-mx-eu-fallback02.hornetsecurity.com","vade-mx-eu-fallback01.hornetsecurity.com"]

Privacy

Trackers or analytics services detected Providers known for analytics, advertising, or behavioral measurement appear in public resources.

["Google"]

Technology footprint

Estimated sovereignty

Dependencies outside Europe Providers legally associated with countries outside Europe appear in the observed scope.

["Cloudflare","Google"]

Jurisdictions to qualify The jurisdiction of some external hosts could not be reliably attributed.

["cdn.jsdelivr.net","vade-mx-fr01.hornetsecurity.com","vade-mx-fr02.hornetsecurity.com","vade-mx-eu-fallback02.hornetsecurity.com","vade-mx-eu-fallback01.hornetsecurity.com"]

Resilience

Concentrated DNS All observed name servers appear to depend on the same operator domain.

["nancy.ns.cloudflare.com","boyd.ns.cloudflare.com"]

Single address observed Public DNS returns a single address at scan time.

["5.250.177.164"]

Transparency

security.txt missing or incomplete No usable /.well-known/security.txt file with a Contact field was observed.

404

Privacy information not found No obvious link to a privacy policy was identified on the page.

origin_host

data_location

Full structured details remain in the JSON report. Missing information is not reconstructed.

06 / THE INSPECTED PAGE

Declared public content

Observed title
JC Confection - Façonnier français de prêt-à-porter haut de gamme
Description
JC Confection est un façonnier de prêt-à-porter haut de gamme & luxe depuis plus de 45 ans, professionnel du textile et de la mode.
Declared structured-data types
BreadcrumbList, EntryPoint, ListItem, PropertyValueSpecification, ReadAction, SearchAction, WebPage, WebSite

The target’s JavaScript is not executed. A website declaration does not certify its identity.

07 / REVIEWED REFERENCES

Reviewed external references

Sources reviewed in administration, not an exhaustive Internet search. They do not modify the historical measurement.

No reviewed external reference recorded.

08 / PUBLIC RESOURCES

Documents and references

09 / TIME CHANGES THE READING

The domain timeline

Initial reference point for this reading.

  1. Displayed reading

Open dedicated history →

10 / KEEP THE READING VERIFIABLE

Evidence, not a score

The twelve angles organise the same evidence. An evidence item reused several times does not become several measurements.

Domain identityReview needed

What is being observed and which public markers identify it?

Observed : Dns address : 5.250.177.164 / Observed : Mail exchanger : vade-mx-eu-fallback01.hornetsecurity.com

Dns address Observed

5.250.177.164

dns

Mail exchanger Observed

vade-mx-eu-fallback01.hornetsecurity.com

dns

Dns nameserver Observed

nancy.ns.cloudflare.com

dns

Mail exchanger Observed

vade-mx-eu-fallback02.hornetsecurity.com

dns

Technical finding Observed

Signal importance : low

dns

Technical finding Observed

Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : low

dns

InfrastructureReview needed

Which public infrastructures appear to serve the service?

Observed : Provider dependency : vade-mx-eu-fallback02.hornetsecurity.com / Observed : Provider dependency : cdn.jsdelivr.net

Provider dependency Observed

vade-mx-eu-fallback02.hornetsecurity.com

provider_observed_once

Provider dependency Observed

cdn.jsdelivr.net

provider_observed_once

Data location Undetermined

Value not available

provider_metadata_does_not_prove_processing_location

Provider dependency Observed

vade-mx-fr01.hornetsecurity.com

provider_observed_once

Provider dependency Observed

vade-mx-fr02.hornetsecurity.com

provider_observed_once

Origin host Undetermined

Value not available

public_edge_does_not_reveal_origin

Encryption and transportObserved

How are public exchanges protected and presented?

Observed : Tls issuer : C = FR, O = Gandi, CN = Gandi RSA Domain Validation Secure Server CA 4 / Not tested : Post-quantum TLS negotiation : No measurement performed

Tls issuer Observed

C = FR, O = Gandi, CN = Gandi RSA Domain Validation Secure Server CA 4

certificate_observed

Post-quantum TLS negotiation Not tested

No measurement performed

client_capability_unavailable

Tls issuer Observed

C = FR, O = Gandi, CN = Gandi RSA Domain Validation Secure Server CA 4

tls

Technical finding Observed

Signal importance : low

headers

Http header Observed

SAMEORIGIN

headers

Http header Observed

Apache

headers

Mail and trustReview needed

Which mail protections and policies are publicly observable?

Observed : SPF policy : softfail / Observed : Dns address : 5.250.177.164

SPF policy Observed

softfail

mail_policy_observed

Dns address Observed

5.250.177.164

dns

Mail exchanger Observed

vade-mx-eu-fallback01.hornetsecurity.com

dns

Dns nameserver Observed

nancy.ns.cloudflare.com

dns

Mail exchanger Observed

vade-mx-eu-fallback02.hornetsecurity.com

dns

Technical finding Observed

Signal importance : low

dns

DNS and governanceReview needed

Which public DNS controls are visible and what remains undetermined?

Observed : Dns address : 5.250.177.164 / Observed : Mail exchanger : vade-mx-eu-fallback01.hornetsecurity.com

Dns address Observed

5.250.177.164

dns

Mail exchanger Observed

vade-mx-eu-fallback01.hornetsecurity.com

dns

Dns nameserver Observed

nancy.ns.cloudflare.com

dns

Mail exchanger Observed

vade-mx-eu-fallback02.hornetsecurity.com

dns

Technical finding Observed

Signal importance : low

dns

Technical finding Observed

Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : low

dns

External dependenciesReview needed

Which external domains, providers or resources does the site visibly depend on?

Observed : Provider dependency : vade-mx-eu-fallback02.hornetsecurity.com / Observed : Provider dependency : cdn.jsdelivr.net

Provider dependency Observed

vade-mx-eu-fallback02.hornetsecurity.com

provider_observed_once

Provider dependency Observed

cdn.jsdelivr.net

provider_observed_once

Provider dependency Observed

vade-mx-fr01.hornetsecurity.com

provider_observed_once

Provider dependency Observed

vade-mx-fr02.hornetsecurity.com

provider_observed_once

Provider dependency Observed

vade-mx-eu-fallback01.hornetsecurity.com

provider_observed_once

Provider dependency Observed

Google

provider_observed_once

Observable technologiesObserved

Which technologies can reasonably be inferred from public traces?

Observed : Technical finding : Signal importance : low / Observed : Http header : SAMEORIGIN

Technical finding Observed

Signal importance : low

headers

Http header Observed

SAMEORIGIN

headers

Http header Observed

Apache

headers

Http header Observed

no-referrer-when-downgrade

headers

Technology Observed

Name : WordPress ; Version exposed : No

technology

Technology Observed

Name : Apache ; Version exposed : No

technology

Public exposureObserved

Which elements, endpoints or artefacts are publicly exposed?

To confirm : Canary statement detected : No / Observed : Technical finding : Evidence : Cloudflare ; Google ; cdn.jsdelivr.net ; vade-mx-eu-fallback01.hornetsecurity.com ; vade-mx-eu-fallback02.hornetsecurity.com ; vade-mx-fr01.hornetsecurity.com ; vade-mx-fr02.hornetsecurity.com ; Signal importance : medium

Canary statement detected To confirm

No

no_known_passive_signature_observed

Technical finding Observed

Evidence : Cloudflare ; Google ; cdn.jsdelivr.net ; vade-mx-eu-fallback01.hornetsecurity.com ; vade-mx-eu-fallback02.hornetsecurity.com ; vade-mx-fr01.hornetsecurity.com ; vade-mx-fr02.hornetsecurity.com ; Signal importance : medium

dependencies

Technical finding Observed

Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : medium

resilience

Technical finding Observed

Evidence : Google ; Signal importance : medium

privacy

Technical finding Observed

Signal importance : low

headers

Http header Observed

SAMEORIGIN

headers

Documentary trustObserved

Which public documents and transparency mechanisms are present?

Observed : Technical finding : Evidence : Cloudflare ; Google ; cdn.jsdelivr.net ; vade-mx-eu-fallback01.hornetsecurity.com ; vade-mx-eu-fallback02.hornetsecurity.com ; vade-mx-fr01.hornetsecurity.com ; vade-mx-fr02.hornetsecurity.com ; Signal importance : medium / Observed : Technical finding : Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : medium

Technical finding Observed

Evidence : Cloudflare ; Google ; cdn.jsdelivr.net ; vade-mx-eu-fallback01.hornetsecurity.com ; vade-mx-eu-fallback02.hornetsecurity.com ; vade-mx-fr01.hornetsecurity.com ; vade-mx-fr02.hornetsecurity.com ; Signal importance : medium

dependencies

Technical finding Observed

Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : medium

resilience

Technical finding Observed

Evidence : Google ; Signal importance : medium

privacy

Technical finding Observed

Signal importance : low

headers

Http header Observed

SAMEORIGIN

headers

Http header Observed

Apache

headers

Security signalsReview needed

Which protections or situations deserve particular attention?

To confirm : Canary statement detected : No / Not tested : Post-quantum TLS negotiation : No measurement performed

Canary statement detected To confirm

No

no_known_passive_signature_observed

Post-quantum TLS negotiation Not tested

No measurement performed

client_capability_unavailable

Technical finding Observed

Evidence : Cloudflare ; Google ; cdn.jsdelivr.net ; vade-mx-eu-fallback01.hornetsecurity.com ; vade-mx-eu-fallback02.hornetsecurity.com ; vade-mx-fr01.hornetsecurity.com ; vade-mx-fr02.hornetsecurity.com ; Signal importance : medium

dependencies

Technical finding Observed

Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : medium

resilience

Tls issuer Observed

C = FR, O = Gandi, CN = Gandi RSA Domain Validation Secure Server CA 4

tls

Technical finding Observed

Evidence : Google ; Signal importance : medium

privacy

Evolution over timeUndetermined

What appeared, disappeared, changed or remained stable since earlier scans?

The available evidence does not yet describe this pillar

Evidence and traceabilityReview needed

Which evidence, methods, dates and limitations support the displayed conclusions?

Observed : Technical finding : Evidence : Cloudflare ; Google ; cdn.jsdelivr.net ; vade-mx-eu-fallback01.hornetsecurity.com ; vade-mx-eu-fallback02.hornetsecurity.com ; vade-mx-fr01.hornetsecurity.com ; vade-mx-fr02.hornetsecurity.com ; Signal importance : medium / Observed : Technical finding : Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : medium

Technical finding Observed

Evidence : Cloudflare ; Google ; cdn.jsdelivr.net ; vade-mx-eu-fallback01.hornetsecurity.com ; vade-mx-eu-fallback02.hornetsecurity.com ; vade-mx-fr01.hornetsecurity.com ; vade-mx-fr02.hornetsecurity.com ; Signal importance : medium

dependencies

Technical finding Observed

Evidence : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Signal importance : medium

resilience

Tls issuer Observed

C = FR, O = Gandi, CN = Gandi RSA Domain Validation Secure Server CA 4

tls

Technical finding Observed

Evidence : Google ; Signal importance : medium

privacy

Dependency provider Observed

Critical : No ; Hosts : www.googletagmanager.com ; Id : google ; Known : Yes ; Name : Google ; Observation count : 1 ; Services : analytics ; captcha ; fonts ; maps ; video ; Tracker : Yes

dependencies

Dependency provider Observed

Critical : Yes ; Hosts : boyd.ns.cloudflare.com ; nancy.ns.cloudflare.com ; Id : cloudflare ; Known : Yes ; Name : Cloudflare ; Observation count : 2 ; Services : cdn ; security ; Tracker : No

dependencies

Evidence record

The filter changes the display. Exports retain all evidence.

mail_exchanger4b58f7f554c8bd3c50
Observed value
vade-mx-eu-fallback01.hornetsecurity.com
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
dns_nameserver95478f19272a5b30fa
Observed value
nancy.ns.cloudflare.com
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
mail_exchanger7a40600a86a933bf54
Observed value
vade-mx-eu-fallback02.hornetsecurity.com
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
http_header3ff105668bebc15c94
Observed value
["max-age=31536000; includeSubDomains"]
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
headers
Method
HTTP response-header inspection
Limitations
A header being present does not prove it is optimal or that the application has no vulnerabilities.
module_finding9181e590a14c9124ae
Observed value
{"evidence":["cdn.jsdelivr.net","www.googletagmanager.com"],"severity":"medium"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
supply_chain
Method
Public page resource and integrity-attribute inspection
Limitations
Missing SRI does not mean a resource is malicious, and static parsing may miss dynamic loads.
module_finding66b41a123967fb4933
Observed value
{"evidence":1,"severity":"low"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
supply_chain
Method
Public page resource and integrity-attribute inspection
Limitations
Missing SRI does not mean a resource is malicious, and static parsing may miss dynamic loads.
module_findingb73dae643260024611
Observed value
{"evidence":["Cloudflare","Google"],"severity":"high"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
sovereignty
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
module_finding4d09156fda9186cd1b
Observed value
{"evidence":null,"severity":"low"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
module_findingc75916ea84540599dd
Observed value
{"evidence":["5.250.177.164"],"severity":"info"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
resilience
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
module_findingf0f8327aa1fc9cca5e
Observed value
{"evidence":404,"severity":"medium"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
transparency
Method
Public transparency artefact inspection
Limitations
A file being present does not prove response speed or overall organizational maturity.
module_finding70c218193c89355932
Observed value
{"evidence":["boyd.ns.cloudflare.com","nancy.ns.cloudflare.com"],"severity":"low"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
mail_policy_flagf0b1f43370b8220550
Observed value
false
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
mail_trust
Method
Public DNS and policy endpoint inspection
Limitations
They do not prove actual deliverability, every recipient’s behavior, or the absence of phishing.
canary_signal7f5b4a11d96bdcd445
Observed value
{"matches":[],"reason":"no_known_passive_signature_observed","signature_version":"2026.09.1","state":"not_observed"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
canary_passive
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
module_findingfa33267707ec65f713
Observed value
{"evidence":null,"severity":"low"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
headers
Method
HTTP response-header inspection
Limitations
A header being present does not prove it is optimal or that the application has no vulnerabilities.
module_finding42bddd86fa87eda2c4
Observed value
{"evidence":{"reason":"No external validating resolver is used; cryptographic validation is intentionally not inferred.","status":"not_tested"},"severity":"info"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
module_finding064112197434787bc4
Observed value
{"evidence":null,"severity":"high"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
mail_trust
Method
Public DNS and policy endpoint inspection
Limitations
They do not prove actual deliverability, every recipient’s behavior, or the absence of phishing.
module_finding81e2fdf5beee388dc5
Observed value
{"evidence":null,"severity":"low"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
headers
Method
HTTP response-header inspection
Limitations
A header being present does not prove it is optimal or that the application has no vulnerabilities.
module_finding0c470fc3c8a26e2f61
Observed value
{"evidence":["cdn.jsdelivr.net","vade-mx-eu-fallback01.hornetsecurity.com","vade-mx-eu-fallback02.hornetsecurity.com","vade-mx-fr01.hornetsecurity.com","vade-mx-fr02.hornetsecurity.com"],"severity":"medium"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
sovereignty
Method
Public observation
Limitations
A visible dependency does not prove data location, actual contractual jurisdiction, or hidden subcontractors.
spf_policy09f98e65f9e91b6463
Observed value
softfail
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
mail_trust
Method
Public DNS and policy endpoint inspection
Limitations
They do not prove actual deliverability, every recipient’s behavior, or the absence of phishing.
module_finding7fedcd8b55194bbd0b
Observed value
{"evidence":null,"severity":"medium"}
Source
release_fallback
Date
2026-09-21T06:20:07+00:00
Collector
dns
Method
Standard DNS resolution and record parsing
Limitations
Public DNS does not prove physical server location, contracts, or global availability.
An explainable reading, not artificial certainty.

Public access, collection budgets and available sources limit this dossier. A hash or signature is not certification of its conclusions.

Report an error or request clarification ↗