benefitscheckup.org
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2001-02-09
- Expires
- 2027-02-09 265 days left
- Updated
- 2026-05-05
- Name servers
-
- ns-1467.awsdns-55.org
- ns-132.awsdns-16.com
- ns-1822.awsdns-35.co.uk
- ns-776.awsdns-33.net
DNS records live
- NS
-
- ns-132.awsdns-16.com
- ns-1467.awsdns-55.org
- ns-1822.awsdns-35.co.uk
- ns-776.awsdns-33.net
- MX
-
- 10 us-smtp-inbound-1.mimecast.com
- 10 us-smtp-inbound-2.mimecast.com
- TXT
-
Show 5 TXT records
amazonses:3OZNnvhw1upmtPWFaZlFb7AcgnOovjA4aU+6vzUku54=facebook-domain-verification=2qlnrzx23f2nzpi207an0ma8eoe3f7google-site-verification=Syfwpp9oIlmCHShmK-EMY2t-shb803do8KEkfU9sWA8google-site-verification=BXNOwEwJl6e1jEwEwfkQt2tih1hQFUmwRFvvet-OliEgoogle-site-verification=aksFiowBUL3-n7t0MFE01tgfYDEspMHmCMJB2moxkucpardot48252=cef9e3b58db21f51c6c7747d24423544933d9f2372032fbeee0bcbcf8f895ecf
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:107.6.102.20/32 ip4:64.95.46.163/32 ip4:64.95.46.161/32 include:us-west-2.amazonses.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 114 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.ncoa.org https://*.everyaction.com https://*.gstatic.com https://*.googleapis.com https://*.livechatinc.com; script-src 'unsafe-eval' 'unsafe-inline' 'self' https://*.bing.com https://*.doubleclick.net https://*.google.com https://*.googleapis.com https://*.clarity.ms https://*.stackadapt.com https://*.livechatinc.com https://*.googleadservices.com/ https://www.googletagmanager.com https://www.google-analytics.com https://qvdt3feo.com/events.js https://snap.licdn.com https://static.ads-twitter.com https://*.facebook.net https://*.gstatic.com; style-src 'unsafe-inline' 'self' https://www.googletagmanager.com https://*.googleapis.com https://*.stackadapt.com ; connect-src 'self' https://*.googleapis.com https://*.googleadservices.com/ https://*.algolia.io https://*.linkedin.com https://*.facebook.com https://cdn.linkedin.oribi.io https://*.stackadapt.com https://*.everyaction.com https://*.doubleclick.net https://*.google.com https://*.google-analytics.com- strict-transport-security
max-age=31536000