athletereg.com

.com crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 1220 ms crawled 2026-05-19

US · 104.21.83.142 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
AthleteReg Online Athletic Event Registration
Description
athleteReg

Technology

CDN
Cloudflare
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • www.bikereg.com×3
  • view.ceros.com×2
  • fonts.googleapis.com×1
  • www.google.com×1

Registration

Registrar
Cloudflare, Inc.
Created
2006-01-11
Expires
2027-01-11 236 days left
Updated
2025-12-12
Name servers
  • ram.ns.cloudflare.com
  • rosa.ns.cloudflare.com

DNS records live

NS
  • ram.ns.cloudflare.com
  • rosa.ns.cloudflare.com
MX
  • 10 aspmx.l.google.com
  • 20 alt1.aspmx.l.google.com
  • 30 alt2.aspmx.l.google.com
  • 40 aspmx2.googlemail.com
  • 50 aspmx3.googlemail.com
TXT
Show 6 TXT records
  • google-site-verification=E7Ux8UVPxeHgWjRn7P7addz_y8Phs1RCbiYUgch5v0s
  • google-site-verification=Masc0zxld1tgE3fBKObWWZ-x0GcfQYT7ktJsl2y8qhI
  • 21ms1sikf5k0ff8o1fgkcjqs8
  • MS=ms25508101
  • box-domain-verification=7347ec44b7b193b344791b2832bb4aaf2de44099291ffe9fff7a0eef50e3704d
  • google-site-verification=9BMaZC3z0OaX6Mdz-mQmbZMHF43zoTcfZhCuDHb4iNA

Email authentication strong

SPF
v=spf1 include:amazonses.com include:_spf.google.com include:_spf.salesforce.com include:4566937.spf07.hubspotemail.net include:mail.zendesk.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@athletereg.com
policy: quarantine
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoSiE4fySMhl/Fk3Mpng/mG4/b9KMTf7dFKKAvY7szJVHNECBxtzFUaqTXhFM8koTL9nmwhbbT4OO71…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

WE1
from 2026-04-26 to 2026-07-25
Expires in 66 days

HTTP security headers

Header hygiene 60/100 Checked live page: https://www.athletereg.com/

present
  • strict-transport-security
  • content-security-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self' *.athletereg.com; upgrade-insecure-requests; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' cdn-prod.securiti.ai js.hscollectedforms.net connect.facebook.net *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.gstatic.com googleads.g.doubleclick.net cdn.metarouter.io js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hubspot.com js.hsleadflows.net js-agent.newrelic.com bam-cell.nr-data.net js-na1.hs-scripts.com *.scorecardresearch.com outside-header.vercel.app ajax.googleapis.com ajax.aspnetcdn.com bam.nr-data.net metarouter-ajs-next-destinations-stage.s3.amazonaws.com *.amplitude.com cdn-prod.securiti.ai *.bikereg.com *.ceros.com *.cloudflareinsights.com *.rudderlabs.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.typekit.net cdn-prod.securiti.ai *.bikereg.com; img-src 'self' data: https: cdn-prod.securiti.ai; connect-src 'self' a
strict-transport-security
max-age=31536000

Linked from (3)