alcoa.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (4)
- cdn.cookielaw.org×1
- js.hcaptcha.com×1
- www.googletagmanager.com×1
- www.onelink-edge.com×1
Social
Registration
- Registrar
- DomainSpot LLC
- Created
- 1986-11-05
- Expires
- 2031-11-04 1995 days left
- Updated
- 2025-12-16
- Name servers
-
- edns1.ultradns.biz
- edns1.ultradns.com
- edns1.ultradns.net
- edns1.ultradns.org
DNS records live
- NS
-
- edns1.ultradns.biz
- edns1.ultradns.com
- edns1.ultradns.net
- edns1.ultradns.org
- MX
-
- 10 mxa-004a5001.gslb.pphosted.com
- 10 mxb-004a5001.gslb.pphosted.com
- TXT
-
Show 13 TXT records
canva-site-verification=pljywwXDtC4E7I8Vr2EuKAsmartsheet-site-validation=_NcJqELstWb4KTayXZ-FWBy0YeKuZFHrpendo-domain-verification=58B527AF-F040-47D6-A313-2CDD7B80A811monday-com-verification=460TVEUXsSHs5Fixiw7NKzDL7U0KJ_REg5xFEVBUlCsgoogle-site-verification=vHSZVBt3gvJ0TafMd3O3g1r7ggjFJoW4xUWy5LiZzIc/Aia0vmOQQYLuugzNuRYotXPJ+HLcXXUnUxe3gkLPdKZa0Ot3SsC6faWjo6lyPQvdSeEGjat0xu65M4jKOfrxw==0hiMANP3ua5POHHl6uHD/Yv/n2gbVCSRzhgqq7FzdMh3dgWeoVX9cxyEi6j2gpaK1ggpqi+MjXxG3xPYB3eR9w==9a8FXZGQJiJ9WJc0HcJiXSVrR61OJWZ2wTJEMWOl56PPoFHydz/Ph0fnI5IWJseJoFT58Exi0owNee6sZE+fhQ==atlassian-domain-verification=JgbSGTDa03h1MeqWN0wa0nP/bPpyEC5RQM8emHNFQGKqVtNbM3+YJOPovlNeKsGksynthesiaapple-domain-verification=4EEIsjeeVGxajAIbibmid=be64a127-492b-41d6-a00a-6da455f6106edocusign=a18f89ac-676b-4ab8-a851-4a52852e8ebd
Email authentication partial
- SPF
-
v=spf1 mx ip4:142.79.177.0/24 ip4:142.79.179.0/24 include:spf.protection.outlook.com include:spf-004a5001.pphosted.com include:spf-004a5002.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarcreports@alcoa.com; ruf=mailto:dmarcreports@alcoa.compolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6Pp7fOcsT1CeaPL5VPi/Ui36we5tx/G4jnvxOugnJfyj/Kset3oTjclwVZyCYGZeGv9legw2I2hdtU… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvKMgdhxJn4Ryfoqw6EWOoShQ4YGnv3Gm/i1K4HLPKL7ljvSzgefc9Xz37DPjyn0FqMDcy/c6+Di98d…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 145 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=()- x-content-type-options
nosniff- content-security-policy
object-src 'none'; script-src 'self' https: 'unsafe-inline'- strict-transport-security
max-age=2592000