123gr.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- ajax.googleapis.com×1
- www.facebook.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 2010-07-02
- Expires
- 2026-07-02 44 days left
- Updated
- 2025-07-01
- Name servers
-
- ns1.hover.com
- ns2.hover.com
DNS records live
- NS
-
- ns1.hover.com
- ns2.hover.com
- MX
-
- 10 mx-cluster-usa01.hornetsecurity.com
- 20 mx-cluster-usa02.hornetsecurity.com
- 30 mx-cluster-usa03.hornetsecurity.com
- 40 mx-cluster-usa04.hornetsecurity.com
- TXT
-
Show 7 TXT records
_f94ap97lrw795sd3jakfaptfpcny8y1MS=ms28068842google-site-verification=SJWcF06EKbmUkrTXjr7yp9XvF4yYmdFmWb8WDkwrsTwknowbe4-site-verification=2d496a4bcb277e18dd98c55e20b3c441pwkj10b3c45gt8r9jdmy8791bqhgpljcgoogle-site-verification=gJWcALIuKv7JbQh5nrajlQZ_iqVoH_WnTY0xsxWpKt4b79mfjg7yfp02mv7vbjvj4nz2nnyzh01
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.hornetsecurity.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 139 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' api.celebrationcinema.com api2.celebrationcinema.com *.google-analytics.com 127.0.0.1 google-analytics.com *.braintreegateway.com *.braintree-api.com *.tiktok.com *.doubleclick.net *.facebook.net https://celebrationcinema.com https://themidtowngr https://123gr https://studioparkgr celebrationcinema.com *.celebrationcinema.com https://barcodeapi.org *.rokt.com *.mountain.com *.linkedin.com; script-src *.googleapis.com *.gstatic.com www.google.com apis.google.com connect.facebook.net ajax.aspnetcdn.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js *.google-analytics.com https://www.youtube.com/iframe_api https://dec.azureedge.net/ munchkin.marketo.net *.googletagmanager.com *.tagmanager.google.com *.google.com *.tiktok.com *.doubleclick.net *.adroll.com *.surveymonkey.com https://celebrationcinema.com https://themidtowngr https://123gr- strict-transport-security
max-age=31536000; includeSubDomains