DNS report
groupelip.com
Complete DNS, mail, web and security analysis.
Cached report
Report created: 2026-09-19 20:33:40 EDT
15 h 15 min ago
Refresh report
DNS cache tools
If you have recently made DNS changes and they are not yet reflected in the report, you can try to flush the DNS cache of these public resolvers: The domain name will be copied to your clipboard automatically when clicking on a button
Category Status Test Details
WHOIS0.1 ms
Domain Status
Source: WHOIS (port 43) whois.ovh.com
RegistrarOVH, SAS
Name Serversdns108.ovh.net
ns108.ovh.net
WHOIS NS match DNS
Updated Date2025-09-12 20:48:50
Creation Date2017-06-07 14:52:14
Registry Expiry Date✅ 2027-06-07 16:52:14+02:00
Domain StatusclientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrar lock enabled
The domain exposes a transfer lock status, such as clientTransferProhibited or serverTransferProhibited.
PARENT0.0 ms
Domain NS records
Nameserver records returned by the parent servers are:

dns108.ovh.net [5.196.41.157, 2001:41d0:d01:200::2] (NO GLUE) [TTL=172800]
ns108.ovh.net [5.135.66.229, 2001:41d0:b00:fc00::2] (NO GLUE) [TTL=172800]

h.gtld-servers.net was kind enough to give us that information.
TLD Parent Check
h.gtld-servers.net has information for your TLD.
This is a good thing as there are some other domain extensions like "co.us" for example that are missing a direct check.
Your nameservers are listed
h.gtld-servers.net has your nameservers listed.
This is a must if you want to be found as anyone that does not know your DNS servers will first ask the parent nameservers.
DNS Parent sent Glue
0 of 2 nameservers sent GLUE.

The parent nameserver a.gtld-servers.net is not sending out GLUE for every nameserver listed, meaning it is sending your nameserver hostnames without their corresponding A records. This is acceptable, but it requires an extra A record lookup, which may slightly delay DNS resolution. This often occurs when nameservers are on a different TLD (e.g., domain.com with nameserver ns.otherdomain.com).
Nameservers A records
Every nameserver listed has A records.
This is a must if you want to be found.
NS3018.1 ms
NS records from your NameServers
NS records returned by the currently delegated nameservers are:

Hostname IP TTL Latency Last SOA change Last WHOIS change
ns108.ovh.net 5.135.66.229 3600 195 ms N/A 2025-09-12 20:48:50
dns108.ovh.net 5.196.41.157 3600 192 ms N/A 2025-09-12 20:48:50

All NS records have the same TTL: 3600 seconds.

Public Resolver
🌐 Cloudflare (GLOBAL)
1.1.1.1
🌐 Google DNS (GLOBAL)
8.8.8.8
🌐 Quad9 (GLOBAL)
9.9.9.9
OpenDNS (US)
208.67.222.222
CIRA Canadian Shield (CA)
149.112.121.10
CleanBrowsing (EU)
185.228.168.9
Quad9 (MX)
149.112.112.112
OpenDNS (ZA)
208.67.220.220
AdGuard DNS (EU)
94.140.14.14
ControlD (EU)
76.76.2.0
Yandex (RU)
77.88.8.8
114DNS (CN)
114.114.114.114
Mismatched NS records
The NS records at all your nameservers are identical to those listed by the parent.
DNS servers responded
All nameservers listed at the parent server responded.
Name of nameservers are valid
All of the NS records that your nameservers report seem valid.
Multiple Nameservers
You have 2 nameservers. This is acceptable, but having 3 or more is recommended according to RFC2182 section 5.
Having 2 nameservers is ok by me.
Missing nameservers reported by parent
All NS records are the same at the parent and at your nameservers.
Missing nameservers reported by your nameservers
All nameservers returned by the parent server are the same as the ones reported by your nameservers.
Domain CNAMEs
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
NSs CNAME check
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
Different subnets
You have nameservers on different subnets.
Recursive Queries
ns108.ovh.net → ✅ does not allow recursion (good)
dns108.ovh.net → ✅ does not allow recursion (good)
Same Glue
Mismatch between parent GLUE and zone A records:
dns108.ovh.net → Parent: 5.196.41.157, 2001:41d0:d01:200::2 | Zone: 5.196.41.157
ns108.ovh.net → Parent: 5.135.66.229, 2001:41d0:b00:fc00::2 | Zone: 5.135.66.229
Make sure both match to comply with DNS best practices.
NS Self-IP Consistency
All nameservers return consistent IP addresses with what they declare in the zone.
Glue for NS records
GLUE was not sent when I asked your nameservers for your NS records.
This is ok but you should know that in this case an extra A record lookup is required.
The nameservers without glue are:
    5.135.66.229
    5.196.41.157
You can fix this by adding A records to your nameservers.
Nameservers are lame
All the nameservers listed at the parent servers answer authoritatively for your domain.
IPs of nameservers are public
Ok. Looks like the IP addresses of your nameservers are public.
This is a good thing because it will prevent DNS delays and other problems.
DNS servers allow TCP connection
OK. Seems all your DNS servers allow TCP connections.
This is a good thing and useful even if UDP connections are used by default.
Different autonomous systems
All authoritative name servers appear to be in the same autonomous system: AS16276.
Using a single AS reduces resiliency and increases the blast radius of network incidents.
Consider hosting your NS records across multiple autonomous systems.


WARNING: Single point of failure.
Stealth NS records sent
Ok. No stealth NS records are sent
DNSSEC709.9 ms
Zone signed
DNSSEC: signedDelegation
RRSIG record present. The zone appears to be DNSSEC-signed.
DNSKEY records
groupelip.com. 3600 IN DNSKEY 257 3 8 AwEAAaZxNHXJPhIZKEWQ1y7mEbyD1vZQ24YN5pppz8lCohQ1GzLdou8K B1jnZCP5Oyu7z5/ho4DvY4FQeyIZlVpT3fx8SdaFJLjum2t0tbRnaJ6M 8INGJf26SoUoXrdfV+wRyfESbnxCidPm3pFrYf5BJuxGU37EUNOLe6Ds Nf2snKoDyM1OdoH4NE+rO7W6Tvb12mTySahFBSsx8dum3VMkSTDxJExN 8ZrICPqm2nfDYWsiefqeyKJm90TE8m/W+d5oOWsCbAhwSWE59osp+ELK LG6Ol1VoWSIlT/I57GeC8ra2V8kSBrJkxqSN6dh7IFrA8NkzCZE9ABsn pfDoOntRLz0=

groupelip.com. 3600 IN DNSKEY 256 3 8 AwEAAbZolR0Zy/IEI3zS50UtShUDYykqYALTDEL/4OXrJvY/UFvBZWq6 VQT3pts269YPJw2ms0Mu2hxj3WsQtjyUpaSrDAkUaIsLELKbP7ONspIj HeyowlrLXNtHylazN0kJLv1tgt6/KhbrqCReilUbBp0oQWzkS3W5OCta 7Dams+hV
DS record in parent
groupelip.com. 21600 IN DS 46201 8 2 CB19AD3F1A75FCF6D5921CC2266073351C66B11BE3210C087916BF58 1AEF249F
NSEC/NSEC3 record
No NSEC or NSEC3 record found when querying a non-existent subdomain.
This may indicate a misconfiguration or lack of proper DNSSEC denial-of-existence support.
Changing nameservers while DNSSEC is active
⚠️ Your domain is currently signed with DNSSEC.
Before changing your nameservers (NS), you must disable DNSSEC at your registrar. Otherwise, your domain may become unreachable due to missing or invalid signatures on the new servers.
SOA0.1 ms
SOA Record
The SOA (Start of Authority) record is:
    Primary nameserver: dns108.ovh.net
    Hostmaster E-mail address: tech@ovh@net
    Serial #: 2087776969
    Refresh: 86400
    Retry: 3600
    Expire: 3600000
    Default TTL: 300
NSs have same SOA serial
OK. All your nameservers agree that your SOA serial number is 2087776969.
SOA MNAME entry
OK. dns108.ovh.net is listed at the parent servers.
SOA Serial
Your SOA serial number is: 2087776969. This appears to follow the recommended YYYYMMDDnn format.
SOA REFRESH
Your SOA REFRESH interval is: 86400. OK.
SOA RETRY
Your SOA RETRY value is: 3600. OK.
SOA EXPIRE
Your SOA EXPIRE number is: 3600000. Looks OK.
SOA MINIMUM TTL
Minimum TTL is low (300). Recommended: 1h+ (3600).
A low minimum TTL results in more frequent DNS queries, which can increase server load. A higher value improves cache efficiency.
MX
...
MX Records
TXT0.1 ms
TXT Records
Host Type Value Size TTL
groupelip.com TXT "MS=ms90640950" 13 3600
groupelip.com TXT "hibp-verify=dweb_l3rpn4m3dgws9eg16sqlmup4" 41 3600
groupelip.com TXT "brevo-code:0699f83be053c3d0194dcaaa0633cf55" 43 3600
groupelip.com TXT "brevo-code:0b3df123a03e57bfd71175c5b1495712" 43 3600
groupelip.com TXT "brevo-code:59310744490df434a5b10aca39912500" 43 3600
groupelip.com TXT "brevo-code:65b4fd448b96a284c95ef9acfa0fb855" 43 3600
groupelip.com TXT "brevo-code:9d4e39dc44b26f78811fe497e13f9ddb" 43 3600
groupelip.com TXT "brevo-code:c7f6e4d2e4595267af4428a3a0000b5b" 43 3600
groupelip.com TXT "brevo-code:d079d2ab43cfdbc23d824ce19f284851" 43 3600
groupelip.com TXT "Sendinblue-code:b763756511ce9b446b59562fb2e91ddc" 48 3600
groupelip.com TXT "anthropic-domain-verification-6e190s=PsQGSHEmf4dmNinn9DBUw671S" 62 3600
groupelip.com TXT "google-site-verification=5MjiaDTJ963iBGDFHbFLZVbEgRtgdIEnugotqIH5oWs" 68 3600
groupelip.com TXT "google-site-verification=Kx0XXHsViRVK4k0OboJuovUsOtOhAK-Ji_zM-olVsH8" 68 3600
groupelip.com TXT "google-site-verification=McifGVMvUx_bdMhwdlftKokseBLObjEdo_ZD7izfP8o" 68 3600
groupelip.com TXT "Jlz37PRBLx5bDw4McBatIaancR7Rx7n8+xz8agzRJnDCM9MGTBkIEiPzotSKzCe4IlOAGOiKtGYI7vdVQnsHbQ==" 88 3600
groupelip.com TXT "v=spf1 include:spf.protection.outlook.com include:spf-de.emailsignatures365.com include:_spf.groupelip.com include:_spf2.groupelip.com include:spf.brevo.com include:spf.mailjet.com ~all" 185 3600
Duplicate TXT records
Multiple TXT records were found for the same host/selector. This can break email authentication.
Host/Selector Type Count Status Details
groupelip.com Verification 3 Warn Multiple verification tokens detected for Google verification token. Only one is usually required.
SPF
...
SPF Analysis
DMARC127.0 ms
DMARC Configuration
DMARC Record was found:
v=DMARC1;p=reject;sp=reject;rua=mailto:[email protected];ri=86400;pct=100;aspf=r;adkim=r

Policy summary:
  • Policy: reject
  • Subdomain policy: reject
  • Percentage applied: 100%
Report settings:Parsed DMARC tags:
TagValueDescription
vDMARC1Version (must be DMARC1)
prejectPolicy for domain
sprejectSubdomain policy
ruamailto:[email protected]Aggregate report URI(s)
rufdefault (ruf=none)Forensic report URI(s)
fodefault (fo=0)Failure reporting options
pct100Percentage of mail to apply policy to
adkimrAlignment mode for DKIM
aspfrAlignment mode for SPF
ri86400Report interval (in seconds)
rfdefault (rf=afrf)Report format
Your real DMARC is:
v=DMARC1; p=reject; sp=reject; rua=mailto:[email protected]; ruf=none; fo=0; pct=100; adkim=r; aspf=r; ri=86400; rf=afrf;
DMARC Evaluation Score: 3/3
✅ Excellent: Your DMARC configuration is optimal.
MTA-STS / TLS-RPT551.7 ms
Mail TLS security
TXT _mta-stsNot found
Policy URLhttps://mta-sts.groupelip.com/.well-known/mta-sts.txt (HTTP 0, policy missing)
Modenot set
Authorized MXnot set
max_agenot set
Policy fileNo valid MTA-STS policy file was fetched.
TXT _smtp._tlsNot found
MTA-STS score 0/5
Recommendations:
  • Publish an _mta-sts TXT record containing v=STSv1; id=. Change id whenever the HTTPS policy changes.
  • Publish the MTA-STS policy at https://mta-sts.groupelip.com/.well-known/mta-sts.txt with version: STSv1, mode, mx, and max_age.
  • Use mode: enforce to prevent delivery to MX hosts that do not satisfy the TLS policy.
  • Add at least one mx: line matching the domain's legitimate MX hosts.
  • Set max_age to at least 604800 seconds once the policy is stable.
  • Publish an _smtp._tls TXT record with v=TLSRPTv1; rua=mailto:tlsrpt@yourdomain to receive TLS reports.
DKIM
...
DKIM Records Detected
BIMI227.2 ms
BIMI Record
No BIMI record found at: default._bimi.groupelip.com.
SSL
...
SSL Certificate Summary
CAA
...
CAA Records
HSTS
...
HSTS
HTTPS
...
HTTPS
HTTPS (DNS)
...
HTTPS DNS record
WWW
...
A Record
AXFR
(Zone Transfer)679.2 ms
AXFR status for the zone
AXFR is refused by the authoritative nameservers for groupelip.com.
Nameservers tested:
    ns108.ovh.net, dns108.ovh.net
Security note
Zone transfers (AXFR) should be disabled in production unless explicitly required and restricted.
Leaving AXFR open allows anyone to enumerate your entire DNS zone (subdomains, MX, TXT, internal hosts, etc.).
PORTS
...
Open ports detected (199.60.103.35)
PORTS
...
Open ports detected (199.60.103.135)
PORTS
Open ports detected (2001:41d0:301::100)
IPv6 scan skipped: this DNSprobe server does not currently have outbound IPv6 connectivity.
REPUTATION
...
IP in blacklists (199.60.103.35)
REPUTATION
...
IP in blacklists (199.60.103.135)
REPUTATION
...
IP in blacklists (2001:41d0:301::100)
DNS found
...
Test Details
Website Preview0.0 ms
Snapshot is generated through DNSprobe's rendering proxy and may be served from a short cache.
Security Headers535.5 ms
Score: 84/100 (B)
Good security, some improvements possible

HeaderValue
HTTP/2
HTTP/2 200
HTTP version reported by the server.
set-cookie
__cf_bm=5ioVwYmSQTSZtMXe0PfcGxop0Ksdtw3TKroJfLTPbMU-1789864430.0716283-1.0.1.1-yulm_.7DjFJoJQeYmvSzHdo5WirgI9KUyKuTY40WVByHOwhBpzIopl693h29eBo1fnFrivK_GZheoQUEF0sdWBFBMdihnzrgr6P3PEBwkxG6SxqTBcn5M5CD09IXnvHJ; HttpOnly; SameSite=None; Secure; Path=/; Domain=www.groupelip.com; Expires=Sun, 20 Sep 2026 01:03:50 GMT _cfuvid=MH7S.Z1iYYUylyjGekHYXYKtLDE.CGTAqGV9QAWyXrE-1789864430.0716283-1.0.1.1-MoZCJ3jwDMXRuo5yQOcom13Psfv8YJGyKkZQc3kWGv8; HttpOnly; SameSite=None; Secure; Path=/; Domain=www.groupelip.com
Session cookies should include the Secure attribute to ensure they are never sent over unencrypted connections.
expires
None
Legacy caching header. Prefer Cache-Control.
cache-control
no-store, no-cache, must-revalidate
Controls caching. For sensitive pages consider 'no-store'.
pragma
None
Legacy HTTP/1.0 directive. Prefer Cache-Control.
content-type
text/html; charset=UTF-8
Declares MIME type; pair with X-Content-Type-Options: nosniff.
content-encoding
br
Compression used for the response (gzip, br…).
vary
accept-encoding
Tells caches which request headers affect the response.
date
Sun, 20 Sep 2026 00:33:50 GMT
Origin date of the response.
age
None
Indicates how long the response has been cached.
x-powered-by
Not defined
May reveal framework/version. Removing lowers fingerprinting.
strict-transport-security
max-age=31536000
Enforces HTTPS for a period, strengthening TLS.
Increase to max-age=31536000 and add includeSubDomains; preload.
Strong HSTS but without 'preload'.
x-xss-protection
Not defined
Deprecated. X-XSS-Protection sets the configuration for the legacy XSS Auditor in older browsers.
The recommended value used to be "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead.
x-content-type-options
Not defined
Stops MIME sniffing. Only valid value: 'nosniff'.
Use X-Content-Type-Options: nosniff.
x-permitted-cross-domain-policies
Not defined
Controls Flash/Adobe cross-domain policies. Use 'none'.
Prefer X-Permitted-Cross-Domain-Policies: none.
referrer-policy
no-referrer-when-downgrade
Controls referrer information sent on navigation.
permissions-policy
Not defined
Restricts powerful features (camera, mic, geolocation…).
Add a Permissions-Policy to restrict powerful features.
expect-ct
Not defined
Deprecated control, should be removed if present.
x-frame-options
Not defined
Protects against clickjacking. Prefer CSP frame-ancestors today.
Add frame-ancestors (CSP) or X-Frame-Options.
content-security-policy
upgrade-insecure-requests
CSP limits content sources to mitigate XSS.
object-src missing; recommend 'object-src 'none''.
base-uri 'self' missing.
frame-ancestors missing.
cross-origin-embedder-policy
Not defined
COEP is part of cross-origin isolation (with COOP).
cross-origin-embedder-policy-report-only
Not defined
COEP in report-only mode (not enforced).
cross-origin-opener-policy
Not defined
COOP isolates browsing context groups when set to same-origin.
cross-origin-opener-policy-report-only
Not defined
COOP in report-only mode (not enforced).
cross-origin-resource-policy
Not defined
CORP restricts who can load this resource.
access-control-allow-origin
Not defined
CORS: which origins are allowed to read this response.
access-control-allow-methods
Not defined
CORS: which methods are allowed.
access-control-allow-headers
Not defined
CORS: which request headers are allowed.
alt-svc
h3=":443"; ma=86400
Advertises alternative services (e.g., HTTP/3 via QUIC).
Other detected headers
Additional headers returned by the server. Shown for information only and not included in the score.
HeaderValue
last-modifiedFri, 18 Sep 2026 14:06:52 GMT
link<https://fonts.googleapis.com>; rel=preconnect,<https://fonts.gstatic.com>; rel=preconnect,<https://fonts.googleapis.com/css2?family=Geologica:wght@300;400;500;600;700&display=swap>; rel=preload; as=style,<https://www.groupelip.com/hubfs/raw_assets/972/public/@projects/groupe-lip/theme/assets/lip.css>; rel=preload; as=style
edge-cache-tagCT-383040915645,CG-147214134,P-147214134,CW-467067985113,CW-467067985121,CW-467067986107,CW-467067986116,CW-467067986127,CW-467067986135,CW-467067986136,CW-467067986137,CW-467067986144,CW-467067987148,CW-467067987149,DB-1753848034,DB-1827825875,DB-1828478182,DB-1828478183,DB-1828485357,DB-1995930839,DB-2064780513,E-467078286539,E-467078286540,E-467078286542,RA-467078286531,PGS-ALL,SW-0,B-381086537936,GC-395764876476,GC-395765262577,TS-382526477531,PROJ-202409873
x-hs-cf-cache-statusHIT
x-hs-cache-configBrowserCache-5s-EdgeCache-0s
x-hs-cache-controls-maxage=36000, max-age=0
x-hs-content-id383040915645
x-hs-hub-id147214134
x-hs-prerenderedFri, 18 Sep 2026 14:06:52 GMT
x-hs-cfworker-meta{"contentType":"SITE_PAGE","resolver":"PreRenderedContentResolver"}
x-hs-portal-id147214134
servercloudflare
cf-raya3dcbdafeec4c521-YUL
Recommended starter configuration (.htaccess)
Starter configuration to copy and adapt. CSP, CORS and cookie rewriting are intentionally commented because they can break some sites if enabled blindly.


#BEGIN SECURITY HEADERS

# -------------------------------------------------------
# Safe baseline
# -------------------------------------------------------
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTPS} !=on
  RewriteCond %{HTTP:X-Forwarded-Proto} !https [NC]
  RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
</IfModule>

Options -Indexes

<IfModule mod_headers.c>
  # Reduce fingerprinting
  # The Server header usually cannot be removed from .htaccess; configure it at the web server level if needed.
  Header always unset X-Powered-By
  Header always unset X-Redirect-By

  # TLS / transport security (only when HTTPS)
  Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" env=HTTPS

  # MIME sniffing protection
  Header always set X-Content-Type-Options "nosniff"

  # Referrer policy
  Header always set Referrer-Policy "strict-origin-when-cross-origin"

  # Adobe cross-domain policy
  Header always set X-Permitted-Cross-Domain-Policies "none"

  # Clickjacking protection (consistent with CSP frame-ancestors 'self')
  Header always set X-Frame-Options "SAMEORIGIN"

  # Cross-Origin isolation headers (sane defaults)
  Header always set Cross-Origin-Opener-Policy "same-origin"
  Header always set Cross-Origin-Resource-Policy "same-origin"
  # COEP is powerful but can break third-party embeds/resources if not CORP/CORS-enabled.
  # Header always set Cross-Origin-Embedder-Policy "require-corp"

  # Deprecated header; modern browsers rely on CSP instead, but some scanners still like to see it.
  Header always set X-XSS-Protection "0"

  # Permissions-Policy (balanced: blocks sensitive features, allows reasonable ones on self)
  Header always set Permissions-Policy "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=(), display-capture=(), autoplay=(self), encrypted-media=(self), fullscreen=(self), picture-in-picture=(self), clipboard-write=(self), publickey-credentials-get=(self)"

  # Vary (keep small; don’t add Referer/User-Agent unless you truly vary by them)
  Header always merge Vary "Accept-Encoding"
</IfModule>

# -------------------------------------------------------
# Cache-Control (HTML pages)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # Apply to HTML responses (works for WordPress permalinks too). Requires Apache 2.4+ expressions.
  # If you do not use a page cache (LiteSpeed Cache, cache plugins, etc.), you can uncomment the line below. Keep it commented if a page cache is active.
  # Header always set Cache-Control "private, no-cache, must-revalidate" "expr=%{CONTENT_TYPE} =~ m#^text/html#"
  # Header always unset Pragma "expr=%{CONTENT_TYPE} =~ m#^text/html#"
  # Header always unset Expires "expr=%{CONTENT_TYPE} =~ m#^text/html#"
</IfModule>

# -------------------------------------------------------
# CSP - Content Security Policy (minimal safe baseline)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # (Keeps your current intent; strengthen later with default-src/script-src/etc.)
  # Adjust img-src, script-src, style-src, font-src, connect-src as needed (e.g., add trusted CDNs).
  # Header always set Content-Security-Policy "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; img-src 'self' data: https:; script-src 'self'; style-src 'self'; font-src 'self' data:; connect-src 'self'; form-action 'self'; upgrade-insecure-requests"
</IfModule>

# -------------------------------------------------------
# CORS - Cross-Origin Ressource Sharing (optional; keep commented unless needed)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # IMPORTANT:
  # - Do NOT enable global CORS unless you have a real API need.
  # If you need CORS, uncomment and set a fixed allowlist.
  # SetEnvIf Origin "^https?://(groupelip\.com|www\.groupelip\.com)(:\d{1,5})?$" CORS_ALLOW_ORIGIN=$0
  # Header always set Access-Control-Allow-Origin "%{CORS_ALLOW_ORIGIN}e" env=CORS_ALLOW_ORIGIN
  # Header always merge Vary "Origin" env=CORS_ALLOW_ORIGIN
  # Header always set Access-Control-Allow-Methods "GET, POST, OPTIONS" env=CORS_ALLOW_ORIGIN
  # Header always set Access-Control-Allow-Headers "Content-Type, Authorization" env=CORS_ALLOW_ORIGIN
  # Header always set Access-Control-Max-Age "86400" env=CORS_ALLOW_ORIGIN
</IfModule>

# -------------------------------------------------------
# Cookies hardening (optional)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # Apache only: uses Header edit/edit* to append Secure/HttpOnly/SameSite when missing. Not valid / not supported reliably on LiteSpeed/OpenLiteSpeed.
  # Header always edit* Set-Cookie "(?i)^((?:(?!;\s*Secure).)+)$" "$1; Secure" env=HTTPS
  # Header always edit* Set-Cookie "(?i)^((?:(?!;\s*HttpOnly).)+)$" "$1; HttpOnly"
  # Header always edit* Set-Cookie "(?i)^((?:(?!;\s*SameSite=).)+)$" "$1; SameSite=Lax"
</IfModule>

# -------------------------------------------------------
# Reporting headers (optional)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # Header always set Reporting-Endpoints "default=\"https://groupelip.com/reporting\""
  # Header always set Cross-Origin-Opener-Policy-Report-Only "same-origin"
  # Header always set Cross-Origin-Embedder-Policy-Report-Only "require-corp"
</IfModule>

#END SECURITY HEADERS
WHOIS143.2 ms
Source: WHOIS (port 43) whois.ovh.com
WHOIS Summary
Domain Name: groupelip.com
Registry Domain ID: REDACTED FOR PRIVACY
Registrar WHOIS Server: whois.ovh.com
Registrar URL: https://ovh.com
Updated Date: 2025-09-12 20:48:50
Creation Date: 2017-06-07 14:52:14
Registrar Registration Expiration Date: 2027-06-07 16:52:14+02:00
Registrar: OVH, SAS
Registrar IANA ID: 433
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +33.972101007
Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registry Registrant ID: REDACTED FOR PRIVACY
Registrant Name: REDACTED FOR PRIVACY
Registrant Organization: REDACTED FOR PRIVACY
Registrant Street: REDACTED FOR PRIVACY
Registrant City: REDACTED FOR PRIVACY
Registrant State/Province: REDACTED FOR PRIVACY
Registrant Postal Code: REDACTED FOR PRIVACY
Registrant Country: FR
Registrant Phone: REDACTED FOR PRIVACY
Registrant Phone Ext: REDACTED FOR PRIVACY
Registrant Fax: REDACTED FOR PRIVACY
Registrant Fax Ext: REDACTED FOR PRIVACY
Registrant Email: REDACTED FOR PRIVACY - Send message to contact by visiting https://ovhcloud.com/en/lp/request-ovhcloud-registered-domain/
Registry Admin ID: REDACTED FOR PRIVACY
Admin Name: REDACTED FOR PRIVACY
Admin Organization: REDACTED FOR PRIVACY
Admin Street: REDACTED FOR PRIVACY
Admin City: REDACTED FOR PRIVACY
Admin State/Province: REDACTED FOR PRIVACY
Admin Postal Code: REDACTED FOR PRIVACY
Admin Country: FR
Admin Phone: REDACTED FOR PRIVACY
Admin Phone Ext: REDACTED FOR PRIVACY
Admin Fax: REDACTED FOR PRIVACY
Admin Fax Ext: REDACTED FOR PRIVACY
Admin Email: REDACTED FOR PRIVACY - Send message to contact by visiting https://ovhcloud.com/en/lp/request-ovhcloud-registered-domain/
Registry Tech ID: REDACTED FOR PRIVACY
Tech Name: REDACTED FOR PRIVACY
Tech Organization: REDACTED FOR PRIVACY
Tech Street: REDACTED FOR PRIVACY
Tech City: REDACTED FOR PRIVACY
Tech State/Province: REDACTED FOR PRIVACY
Tech Postal Code: REDACTED FOR PRIVACY
Tech Country: FR
Tech Phone: REDACTED FOR PRIVACY
Tech Phone Ext: REDACTED FOR PRIVACY
Tech Fax: REDACTED FOR PRIVACY
Tech Fax Ext: REDACTED FOR PRIVACY
Tech Email: REDACTED FOR PRIVACY - Send message to contact by visiting https://ovhcloud.com/en/lp/request-ovhcloud-registered-domain/
Name Server: dns108.ovh.net
Name Server: ns108.ovh.net
DNSSEC: signedDelegation
URL of the ICANN WHOIS Data Problem Reporting System:
>>> Last update of WHOIS database: 2026-06-01T03:28:18Z <<<
For more information on Whois status codes, please visit https://icann.org/epp
############################################################################### # # Welcome to the OVH WHOIS Server. # # whois server : whois.ovh.com check server : check.ovh.com # # The data in this Whois is at your disposal with the aim of supplying you the # information only, that is helping you in the obtaining of the information # about or related to a domain name registration record. OVH Sas make this # information available "as is", and do not guarantee its accuracy. By using # Whois, you agree that you will use these data only for legal purposes and # that, under no circumstances will you use this data to: (1) Allow, enable, # or otherwise support the transmission of mass unsolicited, commercial # advertisement or roughly or requests via the individual mail (courier), # the E-mail (SPAM), by telephone or by fax. (2) Enable high volume, automated, # electronic processes that apply to OVH Sas (or its computer systems). # The copy, the compilation, the re-packaging, the dissemination or the # other use of the Whois base is expressly forbidden without the prior # written consent of OVH. Domain ownership disputes should be settled using # ICANN's Uniform Dispute Resolution Policy: http://www.icann.org/udrp/udrp.htm # We reserve the right to modify these terms at any time. By submitting # this query, you agree to abide by these terms. OVH Sas reserves the right # to terminate your access to the OVH Sas Whois database in its sole # discretion, including without limitation, for excessive querying of # the Whois database or for failure to otherwise abide by this policy. # # L'outil du Whois est à votre disposition dans le but de vous fournir # l'information seulement, c'est-à-dire vous aider dans l'obtention de # l'information sur ou lié à un rapport d'enregistrement de nom de domaine. # OVH Sas rend cette information disponible "comme est," et ne garanti pas # son exactitude. En utilisant notre outil Whois, vous reconnaissez que vous # emploierez ces données seulement pour des buts légaux et ne pas utiliser cet # outil dans les buts suivant: (1) la transmission de publicité non sollicitée, # commerciale massive ou en gros ou des sollicitations via courrier individuel, # le courrier électronique (c'est-à-dire SPAM), par téléphone ou par fax. (2) # l'utilisation d'un grand volume, automatisé des processus électroniques qui # soulignent ou chargent ce système de base de données Whois vous fournissant # cette information. La copie de tout ou partie, la compilation, le # re-emballage, la dissémination ou d'autre utilisation de la base Whois sont # expressément interdits sans consentement écrit antérieur de OVH. Un désaccord # sur la possession d'un nom de domaine peut être résolu en suivant la Uniform # Dispute Resolution Policy de l'ICANN: http://www.icann.org/udrp/udrp.htm # Nous nous réservons le droit de modifier ces termes à tout moment. En # soumettant une requête au Whois vous consentez à vous soumettre à ces termes.
# local time : 2026-09-20T00:33:41Z # gmt time : 2026-09-20T00:33:41Z # last modify : 2026-06-01T03:28:18Z
http: //wdprs.internic.net/
WHOIS RAW
Domain Name: groupelip.com
Registry Domain ID: REDACTED FOR PRIVACY
Registrar WHOIS Server: whois.ovh.com
Registrar URL: https://ovh.com
Updated Date: 2025-09-12T20:48:50Z
Creation Date: 2017-06-07T14:52:14Z
Registrar Registration Expiration Date: 2027-06-07T16:52:14+02:00
Registrar: OVH, SAS
Registrar IANA ID: 433
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +33.972101007
Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registry Registrant ID: REDACTED FOR PRIVACY
Registrant Name: REDACTED FOR PRIVACY
Registrant Organization: REDACTED FOR PRIVACY
Registrant Street: REDACTED FOR PRIVACY
Registrant City: REDACTED FOR PRIVACY
Registrant State/Province: REDACTED FOR PRIVACY
Registrant Postal Code: REDACTED FOR PRIVACY
Registrant Country: FR
Registrant Phone: REDACTED FOR PRIVACY
Registrant Phone Ext: REDACTED FOR PRIVACY
Registrant Fax: REDACTED FOR PRIVACY
Registrant Fax Ext: REDACTED FOR PRIVACY
Registrant Email: REDACTED FOR PRIVACY - Send message to contact by visiting https://ovhcloud.com/en/lp/request-ovhcloud-registered-domain/
Registry Admin ID: REDACTED FOR PRIVACY
Admin Name: REDACTED FOR PRIVACY
Admin Organization: REDACTED FOR PRIVACY
Admin Street: REDACTED FOR PRIVACY
Admin City: REDACTED FOR PRIVACY
Admin State/Province: REDACTED FOR PRIVACY
Admin Postal Code: REDACTED FOR PRIVACY
Admin Country: FR
Admin Phone: REDACTED FOR PRIVACY
Admin Phone Ext: REDACTED FOR PRIVACY
Admin Fax: REDACTED FOR PRIVACY
Admin Fax Ext: REDACTED FOR PRIVACY
Admin Email: REDACTED FOR PRIVACY - Send message to contact by visiting https://ovhcloud.com/en/lp/request-ovhcloud-registered-domain/
Registry Tech ID: REDACTED FOR PRIVACY
Tech Name: REDACTED FOR PRIVACY
Tech Organization: REDACTED FOR PRIVACY
Tech Street: REDACTED FOR PRIVACY
Tech City: REDACTED FOR PRIVACY
Tech State/Province: REDACTED FOR PRIVACY
Tech Postal Code: REDACTED FOR PRIVACY
Tech Country: FR
Tech Phone: REDACTED FOR PRIVACY
Tech Phone Ext: REDACTED FOR PRIVACY
Tech Fax: REDACTED FOR PRIVACY
Tech Fax Ext: REDACTED FOR PRIVACY
Tech Email: REDACTED FOR PRIVACY - Send message to contact by visiting https://ovhcloud.com/en/lp/request-ovhcloud-registered-domain/
Name Server: dns108.ovh.net
Name Server: ns108.ovh.net
DNSSEC: signedDelegation
URL of the ICANN WHOIS Data Problem Reporting System:
http://wdprs.internic.net/
>>> Last update of WHOIS database: 2026-06-01T03:28:18Z <<<

For more information on Whois status codes, please visit https://icann.org/epp 

###############################################################################
#
# Welcome to the OVH WHOIS Server.
#
# whois server  : whois.ovh.com       check server  : check.ovh.com
#
# The data in this Whois is at your disposal  with the aim of supplying you the
# information only,  that is helping you  in the obtaining  of  the information
# about  or  related to a domain name registration record.   OVH Sas  make this
# information available "as is", and  do not  guarantee its accuracy.  By using
# Whois,  you agree that you will use these data  only for  legal  purposes and
# that,  under no circumstances will you use this data to:  (1) Allow,  enable,
# or  otherwise  support  the  transmission  of  mass  unsolicited,  commercial
# advertisement  or  roughly  or  requests  via the  individual mail (courier),
# the E-mail (SPAM), by telephone or by fax. (2) Enable high volume, automated,
# electronic  processes  that  apply  to  OVH  Sas   (or its computer systems).
# The copy,   the compilation,   the re-packaging,   the dissemination   or the
# other  use  of  the Whois base  is  expressly  forbidden  without  the  prior
# written consent of  OVH.  Domain  ownership  disputes should be settled using
# ICANN's Uniform Dispute Resolution Policy: http://www.icann.org/udrp/udrp.htm
# We reserve the right  to  modify  these  terms  at  any  time.  By submitting
# this query,  you agree to  abide by these terms.  OVH Sas  reserves the right
# to  terminate  your  access  to  the  OVH Sas  Whois  database  in  its  sole
# discretion,   including   without   limitation,   for  excessive  querying of
# the Whois database  or  for  failure  to  otherwise  abide  by  this  policy.
#
# L'outil du Whois  est  à  votre  disposition  dans  le  but  de  vous fournir
# l'information  seulement,  c'est-à-dire  vous   aider   dans  l'obtention  de
# l'information  sur ou lié à un  rapport  d'enregistrement  de nom de domaine.
# OVH Sas rend  cette information disponible  "comme est,"  et  ne garanti pas
# son exactitude. En utilisant  notre outil  Whois, vous  reconnaissez que vous
# emploierez ces données seulement pour  des buts légaux et ne pas utiliser cet
# outil dans les buts suivant: (1) la transmission de publicité non sollicitée,
# commerciale massive ou en gros ou des sollicitations via courrier individuel,
# le courrier électronique (c'est-à-dire SPAM),  par  téléphone ou par fax. (2)
# l'utilisation d'un grand volume,  automatisé  des processus électroniques qui
# soulignent ou chargent ce système de base de données  Whois  vous fournissant
# cette  information.   La  copie   de  tout  ou  partie,   la compilation,  le
# re-emballage,  la dissémination ou d'autre utilisation de la base Whois  sont
# expressément interdits sans consentement écrit antérieur de OVH. Un désaccord
# sur la possession d'un nom de domaine peut être résolu en suivant la  Uniform
# Dispute  Resolution  Policy  de  l'ICANN:  http://www.icann.org/udrp/udrp.htm
# Nous nous  réservons  le  droit  de  modifier  ces  termes  à tout moment. En
# soumettant une requête au Whois vous consentez à vous soumettre à ces termes.

# local time : 2026-09-20T00:33:41Z
# gmt time : 2026-09-20T00:33:41Z
# last modify : 2026-06-01T03:28:18Z

RDAP
142.6 ms
Source: RDAP rdap.org → rdap.verisign.com → rdap.ovh.com
Domain Name:GROUPELIP.COM
Registry Domain ID:2131534725_DOMAIN_COM-VRSN
RDAP self:https://rdap.verisign.com/com/v1/domain/groupelip.com
Updated Date:2026-06-08 08:23:11
Creation Date:2017-06-07 14:52:14
Registry Expiry Date:✅ 2027-06-07 14:52:14
Registrar:OVH sas
Registrar Abuse Contact Email:[email protected]
Registrar Abuse Contact Phone:+33.972101007
Domain Status:clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Name Servers:dns108.ovh.net
ns108.ovh.net
WHOIS NS match DNS
DNSSEC:signed (delegationSigned=true)
DS records: 1
RDAP notices:Terms of Service — https://www.verisign.com/domain-names/registration-data-access-protocol/terms-service/index.xhtml
Status Codes — https://icann.org/epp
RDDS Inaccuracy Complaint Form — https://icann.org/wicf
Registrar
Registrar:
Name OVH sas
Handle: 433
Abuse contact:
Phone +33.972101007
RDAP JSON (raw)
{
    "objectClassName": "domain",
    "handle": "2131534725_DOMAIN_COM-VRSN",
    "ldhName": "GROUPELIP.COM",
    "links": [
        {
            "value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
            "rel": "self",
            "href": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
            "type": "application/rdap+json"
        },
        {
            "value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
            "rel": "related",
            "href": "https://rdap.ovh.com/domain/GROUPELIP.COM",
            "type": "application/rdap+json"
        }
    ],
    "status": [
        "client delete prohibited",
        "client transfer prohibited"
    ],
    "entities": [
        {
            "objectClassName": "entity",
            "handle": "433",
            "roles": [
                "registrar"
            ],
            "links": [
                {
                    "href": "http://www.ovh.com",
                    "type": "text/html",
                    "value": "https://rdap.ovh.com/",
                    "rel": "about"
                }
            ],
            "publicIds": [
                {
                    "type": "IANA Registrar ID",
                    "identifier": "433"
                }
            ],
            "vcardArray": [
                "vcard",
                [
                    [
                        "version",
                        [],
                        "text",
                        "4.0"
                    ],
                    [
                        "fn",
                        [],
                        "text",
                        "OVH sas"
                    ]
                ]
            ],
            "entities": [
                {
                    "objectClassName": "entity",
                    "roles": [
                        "abuse"
                    ],
                    "vcardArray": [
                        "vcard",
                        [
                            [
                                "version",
                                [],
                                "text",
                                "4.0"
                            ],
                            [
                                "fn",
                                [],
                                "text",
                                ""
                            ],
                            [
                                "tel",
                                {
                                    "type": "voice"
                                },
                                "uri",
                                "tel:+33.972101007"
                            ],
                            [
                                "email",
                                [],
                                "text",
                                "[email protected]"
                            ]
                        ]
                    ]
                }
            ]
        }
    ],
    "events": [
        {
            "eventAction": "registration",
            "eventDate": "2017-06-07T14:52:14Z"
        },
        {
            "eventAction": "expiration",
            "eventDate": "2027-06-07T14:52:14Z"
        },
        {
            "eventAction": "last changed",
            "eventDate": "2026-06-08T08:23:11Z"
        },
        {
            "eventAction": "last update of RDAP database",
            "eventDate": "2026-09-20T00:33:36Z"
        }
    ],
    "secureDNS": {
        "delegationSigned": true,
        "dsData": [
            {
                "keyTag": 46201,
                "algorithm": 8,
                "digestType": 2,
                "digest": "CB19AD3F1A75FCF6D5921CC2266073351C66B11BE3210C087916BF581AEF249F"
            }
        ]
    },
    "nameservers": [
        {
            "objectClassName": "nameserver",
            "ldhName": "DNS108.OVH.NET"
        },
        {
            "objectClassName": "nameserver",
            "ldhName": "NS108.OVH.NET"
        }
    ],
    "rdapConformance": [
        "rdap_level_0",
        "icann_rdap_technical_implementation_guide_1",
        "icann_rdap_response_profile_1"
    ],
    "notices": [
        {
            "title": "Terms of Service",
            "description": [
                "Service subject to Terms of Use."
            ],
            "links": [
                {
                    "href": "https://www.verisign.com/domain-names/registration-data-access-protocol/terms-service/index.xhtml",
                    "type": "text/html",
                    "value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
                    "rel": "terms-of-service"
                }
            ]
        },
        {
            "title": "Status Codes",
            "description": [
                "For more information on domain status codes, please visit https://icann.org/epp"
            ],
            "links": [
                {
                    "href": "https://icann.org/epp",
                    "type": "text/html",
                    "value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
                    "rel": "glossary"
                }
            ]
        },
        {
            "title": "RDDS Inaccuracy Complaint Form",
            "description": [
                "URL of the ICANN RDDS Inaccuracy Complaint Form: https://icann.org/wicf"
            ],
            "links": [
                {
                    "href": "https://icann.org/wicf",
                    "type": "text/html",
                    "value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
                    "rel": "help"
                }
            ]
        }
    ]
}

You like this tool?

Buy Me A Coffee

Processed in 0.01 seconds.
Made with with PHP and a bit of JS.
Lines of code: 20,351

⚙️ Configuration
(Check / Uncheck All)