amazontrust.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 2007-05-11
- Expires
- 2027-05-11 357 days left
- Updated
- 2026-04-09
- Name servers
-
- ns-1249.awsdns-28.org
- ns-1794.awsdns-32.co.uk
- ns-419.awsdns-52.com
- ns-612.awsdns-12.net
DNS records live
- NS
-
- ns-1249.awsdns-28.org
- ns-1794.awsdns-32.co.uk
- ns-419.awsdns-52.com
- ns-612.awsdns-12.net
- MX
-
- 10 inbound-smtp.us-east-1.amazonaws.com
Email authentication strong
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:report@dmarc.amazon.com; ruf=mailto:report@dmarc.amazon.compolicy: reject (enforced) - DKIM
-
Show 12 DKIM selectors
- default:
v=DKIM1; p= - google:
v=DKIM1; p= - selector1:
v=DKIM1; p= - selector2:
v=DKIM1; p= - k1:
v=DKIM1; p= - k2:
v=DKIM1; p= - mail:
v=DKIM1; p= - dkim:
v=DKIM1; p= - s1:
v=DKIM1; p= - s2:
v=DKIM1; p= - mxvault:
v=DKIM1; p= - smtpapi:
v=DKIM1; p=
selectors probed - default:
Certificate (current)
Amazon RSA 2048 M01
Expires in 126 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; default-src 'self'; connect-src 'self' https://cognito-identity.us-east-1.amazonaws.com/ https://sts.us-east-1.amazonaws.com/ https://dataplane.rum.us-east-1.amazonaws.com https://*.captcha.awswaf.com/ https://*.captcha-sdk.awswaf.com/ https://*.token.awswaf.com/; script-src 'self' 'nonce-ff5c4c7d3959b12082465d255181c9ce' https://*.captcha.awswaf.com/ https://*.captcha-sdk.awswaf.com/ https://*.token.awswaf.com/; script-src-attr 'nonce-ff5c4c7d3959b12082465d255181c9ce'; style-src 'self' https://*.amazon.dev 'unsafe-inline' https://*.awswaf.com/; font-src 'self' data: https://*.media-amazon.com https://*.awswaf.com/; img-src 'self' data: blob: https://internal-cdn.amazon.com; object-src 'none'; frame-src 'self' blob:; frame-ancestors 'none'; worker-src 'self' blob:; base-uri 'none'- strict-transport-security
max-age=47304000; includeSubDomains