ballardspahr.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Nuxt
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (3)
- cdn.cookielaw.org×2
- use.typekit.net×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1995-04-03
- Expires
- 2028-04-04 684 days left
- Updated
- 2023-02-04
- Name servers
-
- ns11.constellix.com
- ns21.constellix.com
- ns31.constellix.com
- ns41.constellix.net
- ns51.constellix.net
- ns61.constellix.net
DNS records live
- NS
-
- ns11.constellix.com
- ns21.constellix.com
- ns31.constellix.com
- ns41.constellix.net
- ns51.constellix.net
- ns61.constellix.net
- MX
-
- 10 mxa-00191001.gslb.pphosted.com
- 10 mxb-00191001.gslb.pphosted.com
- TXT
-
ciscocidomainverification=6fe25166c53b3b2d492a075c185c39550276c20dea9bd490243e265bb8a8343cpaloaltonetworks-site-verification=b9365be10172eac4bf85825fd7e48c9781044c1264d19d06bf94c32fc5f4eaf9_w5ay61uq6u261ohvrfc6m8toceu2hhb
- Verified for
-
- Adobe
- Atlassian
- DocuSign
- Microsoft 365
- OneTrust
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:ballardspahr.com._nspf.vali.email include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:_spf.sendergen.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email; ruf=mailto:postmaster@ballardspahr.com; fo=1policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuns1aHdoVjV3sXO3SF/3XLntKhCe3w/qUcr4o7BDg5WPIi2sRovvQn8THw0Xyc/s1gn2tS4o4gEEZ5… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApdths7RznPtnZNnkS6EANW61u/0eycVPwaX5/bjvZ+9SNJsWzL0yTJq0LM+ykeA6yvBZMe/QWkOsGe… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 309 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-eval' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.google.com *.gstatic.com *.googleapis.com *.jquery.com *.onenorth.com *.oniqa.com *.onistaged.com *.amazonaws.com *.googletagmanager.com *.google-analytics.com *.google.com *.vimeo.com *.visme.co *.hotjar.com cdn.cookielaw.org geolocation.onetrust.com responses.ballardspahr.com app.powerbi.com https://snap.licdn.com; img-src 'self' data: ballardspahr.vuturevx.com cdn.cookielaw.org *.google-analytics.com *.linkedin.com *.cookiebot.com *.doubleclick.net *.google-analytics.com *.hotjar.com; style-src 'self' 'unsafe-inline' *.typekit.net; font-src 'self' data: *.typekit.net; frame-src 'self' *.google.com *.doubleclick.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.hotjar.com *.libsyn.com; connect-src 'self' *.doubleclick.net *.google-analytics.com cdn.cookielaw.org geolocation.onetrust.com https://px.ads.linkedin.com *.hotjar.com;- strict-transport-security
max-age=31536000; includeSubDomains;