bch.org
HTML metadata
Technology
- Server
- nginx
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (2)
- analytics.scorpion.co×1
- use.typekit.net×1
Social
Contact
- Phone
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1995-11-30
- Expires
- 2034-11-29 3116 days left
- Updated
- 2024-12-05
- Name servers
-
- garrett.ns.cloudflare.com
- gene.ns.cloudflare.com
DNS records live
- NS
-
- garrett.ns.cloudflare.com
- gene.ns.cloudflare.com
- MX
-
- 10 esa01.bch.org
- 10 esa02.bch.org
- TXT
-
Show 10 TXT records
smartsheet-site-validation=gkh4mkTGfln8VzTIcqARf8hiDaE21Mc3_g0zzfkdljm09nrx7wbid5mgyezxv9bv_lgtnyqnjv8ddh6t0c7d06xsx8suqjq4apple-domain-verification=8JD5pn0s4O12RESRcisco-ci-domain-verification=15720a44ca7d7daed7854dc04e892c7bdca30991b77e9fa119e41a9fa293662dgoogle-site-verification=_WAi7r2Jq1CD2tf81VAgYDTgbhw0RqDZMl3y1aj7aeQgoogle-site-verification=p0W2yM-2NSxQrIyAuxyk2ce7nRQMWvFG29K_MO6XE0Qgoogle-site-verification=pdi46AyWwXA5Ze8Isj-S8UPro2Z5w9LotwbQvYvXDzwgoogle-site-verification=qYfOglZGWmPa6iJTsHMkKY5wyaWhy5F-yHaAigKz7nIgoogle-site-verification=sVLK1jyGE8pv8EbXvZSIsIoXf1jXXy7n-MILGytiCHc
Email authentication partial
- SPF
-
v=spf1 include:res.cisco.com ip4:63.251.143.30 ip4:64.74.110.101 ip4:69.161.206.28 ip4:69.161.206.29 ip4:167.89.94.126 include:servers.mcsv.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; aspf=s; rua=mailto:dmarcrep@bch.org; ruf=mailto:dmarcfor@bch.org; fo=0:1:d:s;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 42 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * blob: data: cid:; img-src * data: cid: 'unsafe-inline'; media-src * data: blob:; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src * blob: data: 'unsafe-inline'; style-src-elem * blob: data: 'unsafe-inline'; font-src * data:- strict-transport-security
max-age=63072000; includeSubDomains; preload