barreoperahouse.org

.org crawl

First seen 2026-04-16 · Last seen 2026-05-08 · ok HTTP/1.1 200 2178 ms crawled 2026-05-11

US · 67.18.65.7 · AS36351 IBM Cloud

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Barre Opera House - Vermont Shows, Concerts, Community Events | Official Website - Barre Opera House
Description
Official website of the historic Barre Opera House, central Vermont's premier performing arts facility. This 1899 theater is the cultural cornerstone of Barre.

Technology

Server
nginx
Analytics
  • Google Tag Manager
Cookie consent
  • Termly

Third-party hosts loaded (4)

  • ajax.googleapis.com×1
  • app.termly.io×1
  • maxcdn.bootstrapcdn.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone
Address
St. Barre, VT 05641

Registration

Registrar
Wild West Domains, LLC
Created
2000-04-03
Expires
2027-04-03 317 days left
Updated
2026-04-04
Name servers
  • ns1.modx.cloud
  • ns2.modx.cloud
  • ns3.modx.cloud
  • ns4.modx.cloud
  • ns5.modx.cloud

DNS records live

NS
  • ns1.modx.cloud
  • ns2.modx.cloud
  • ns3.modx.cloud
  • ns4.modx.cloud
  • ns5.modx.cloud
MX
Show 7 MX records
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 10 aspmx4.googlemail.com
  • 10 aspmx5.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com

Email authentication partial

SPF
v=spf1 ip4:173.192.73.34 a mx include:aspmx.googlemail.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD2bYWQLI5Pmiapzv3J7H+x2AdLpZftESxorJV3Y8nb7awMXgnlYvGGJgIeBOlhyLBMaORfH6uom2dojZ42x6…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

R12
from 2026-03-21 to 2026-06-19
Expires in 29 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://barreoperahouse.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=()
x-content-type-options
nosniff
content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval'; img-src * data: blob: 'unsafe-inline'; font-src * data:
strict-transport-security
max-age=31536000; includeSubdomains, max-age=31536000; includeSubdomains

Links to (18)

Linked from (1)