balladhealth.org
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (4)
- cdn.jsdelivr.net×2
- fast.wistia.net×2
- static.legitscript.com×1
- use.typekit.net×1
Social
Contact
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2016-08-04
- Expires
- 2027-08-04 440 days left
- Updated
- 2024-09-18
- Name servers
-
- ns1.wellmont.org
- ns2.wellmont.org
DNS records live
- NS
-
- ns1.balladhealth.org
- ns2.balladhealth.org
- MX
-
- 10 balladhealth-org.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
CSAITJKTA6IFTG59HGSF4EHVDCdov95l5b424a082nigiji4aa85M5aIsHav5mMNa74R2NqsNSjcsvbFKkWbRK168QcaC/ghrj9enKZzb2F0zMy4DkpL3g+ZVJWn+tbyjT2gV2kIeA==56YP5ONXPIW62RG0ZLBY65XFGQ5JZHATLLALNK00Sciscocidomainverification=8237fa5a8b73a88e8243c04670d8c9e79db67412fb77aed2ee93f20a6b02e65
- Verified for
-
- Adobe
- Apple
- Microsoft 365
- Smartsheet
Email authentication strong
- SPF
-
v=spf1 mx ip4:199.21.145.0/24 ip4:75.141.70.0/24 ip4:151.102.241.0/24 ip4:104.46.3.207 include:salsalabs.org include:spf.protection.outlook.com include:spfc._spf.cisco.com include:outboundmail.blackbaud.net -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; ruf=mailto:dmarc-security@balladhealth.org; rua=mailto:dmarc-security@balladhealth.org; adkim=r; aspf=rpolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7WZ/XawuFZvBJrjg4LLJxUromalaNTMbLeBWuMJAmBpchiMfhnCKsmwfciTwJMI/vzGVhMja9oqfou5pj61… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqUFZlFwUQoOgZvYl5zSehVc8UASd18NCySFFrKQOr2QLCATbKUq8tr/5JSXwidxdOCceXYMUp1d1DlpQn7… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyuNLGyJ07l+m7Jh1IcMbD4FxCY9EcZUQ4CV1Yz5dIMDblY4oFLNpTA9u7ZPhpmAecJMfh5M+IYSsYZnPLe…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 305 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src https: data: wss://*.hotjar.com wss://web-dev.hyro.ws wss://web.hyro.ws wss://ws.paradox.ai/ 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self'; report-uri /report-csp-violation- strict-transport-security
max-age=2592000; includeSubDomains
Links to (5)
- facebook.com×3
- instagram.com×3
- linkedin.com×3
- x.com×3
- youtube.com×3