askdirect.ie
HTML metadata
Technology
- Server
- Apache
- jQuery
- 3.3.1 known XSS (<3.5)
Third-party hosts loaded (4)
- code.jquery.com×1
- e63961dc.sibforms.com×1
- static.revolutionaries.ie×1
- www.google.com×1
Contact
DNS records live
- NS
-
- ns1.anu.net
- ns2.anu.net
- ns3.anu.net
- MX
-
Show 7 MX records
- 0 aspmx.l.google.com
- 10 alt1.aspmx.l.google.com
- 10 alt2.aspmx.l.google.com
- 20 aspmx2.googlemail.com
- 20 aspmx3.googlemail.com
- 20 aspmx4.googlemail.com
- 20 aspmx5.googlemail.com
- Verified for
-
- Brevo
Email authentication partial
- SPF
-
v=spf1 ip4:193.189.141.156 a:mail.anu.net a:spamtitan.anu.net a:ams2-c6-1.anuhosting.net include:_spf.google.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.compolicy: none (monitoring only) - DKIM
-
- mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - mail:
Certificate (current)
E8
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-resource-policy
- findings
-
- missing Content Security Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),camera=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),payment=(),usb=(),interest-cohort=(),browsing-topics=()- x-content-type-options
nosniff- strict-transport-security
max-age=16070400; includeSubDomains- cross-origin-resource-policy
same-origin- content-security-policy-report-only
default-src 'self'; base-uri 'none'; object-src 'none'; form-action 'self'; frame-ancestors 'none'; frame-src 'self' disqus.com e63961dc.sibforms.com www.google.com; script-src 'nonce-d1lrUk1Rbm1KeXdDajBuZ01HNkRhbEg4eEx4c081am' 'strict-dynamic' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' fonts.googleapis.com static.revolutionaries.ie; font-src 'self' fonts.gstatic.com; connect-src 'self' px.ads.linkedin.com region1.google-analytics.com www.facebook.com www.google-analytics.com; img-src 'self' data: *.ads.linkedin.com referrer.disqus.com www.facebook.com www.googletagmanager.com www.revolutionaries.ie; upgrade-insecure-requests; report-uri https://csp.revolutionaries.ie/api/r/csp/; report-to default;