ab-invest.net
HTML metadata
Registration
- Registrar
- Register.com - Network Solutions, LLC
- Created
- 2007-01-28
- Expires
- 2031-01-28 1714 days left
- Updated
- 2021-01-28
- Name servers
-
- ns1.ab-invest.net
- ns2.arabbank.com.jo
DNS records
Email authentication strong
- SPF
-
v=spf1 mx ip4:94.200.22.251 ip4:94.56.109.197 ip4:37.75.144.175 ip4:37.75.144.57 ip4:37.75.144.154 ip4:37.75.147.122 ip4:37.75.147.124 -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;sp=reject;pct=100;rua=mailto:Quarantine.Admin@arabbank.com.jo;ruf=mailto:Quarantine.Admin@arabbank.com.jo,mailto:SECIR@Arabbank.com.jo;ri=86400;aspf=s;adkim=s;fo=1policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
DigiCert EV RSA CA G2
Expires in 209 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
accelerometer=(self), ambient-light-sensor=(self), autoplay=(self), battery=(self), camera=(self), display-capture=(self), document-domain=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), layout-animations=(self), magnetometer=(self), microphone=(self), midi=(self), oversized-images=(self), payment=(self), picture-in-picture=(*), publickey-credentials-get=(self), sync-xhr=(self), usb=(self), wake-lock=(self), xr-spatial-tracking=(self)- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; connect-src 'self'; font-src 'self'; frame-src 'self' *.google.com; img-src 'self' data: *.exchange.jo; manifest-src 'self'; object-src 'self'; prefetch-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.exchange.jo ajax.googleapis.com *.google.com *.gstatic.com; style-src 'self' 'unsafe-inline' *.exchange.jo; media-src 'self'; form-action 'self'; worker-src 'self'; frame-ancestors 'self'; child-src 'self'; require-sri-for script- strict-transport-security
max-age=16070400; includeSubDomains, max-age=16070400