bestvetsolutions.com
HTML metadata
Technology
- Stack
- Java
- Fonts
-
- Google Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (3)
- fonts.googleapis.com×3
- fonts.gstatic.com×1
- www.youtube.com×1
Contact
- Phone
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 2003-01-17
- Expires
- 2030-01-17 1324 days left
- Updated
- 2020-12-22
- Name servers
-
- ns1.netins.net
- ns2.netins.net
DNS records live
- NS
-
- ns1d.aureon.com
- ns3k.aureon.com
- MX
-
- 0 bestvetsolutions-com.mail.protection.outlook.com
- Verified for
-
- Apple
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 ip4:208.126.14.5 include:spf.protection.outlook.com ?include:spf.globalreach.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDkYLqJC4BzWTNwBYJ8YUsv4XwXeBUhUig/Xd1RSyENTshUWrrtT+QwglsyhHk/AldTDcLG6VRARO98J59un3… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0xMOynKgWiIy1IbH5YlmrDeGGdbwbnLMlCzWIFElHm0JdpzbhnGwRQOUDDW9lhKOPMG7MTw3+SVPbz… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
YR1
Expires in 88 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' *.globalreach.com analytics.globalreach.com *.authorize.net *.stripe.com lib.paymentjs.firstdata.com *.paypalobjects.com www.paypalobjects.com code.jquery.com *.googleapis.com ct.pinterest.com s.pinimg.com www.facebook.com connect.facebook.net *.sharethis.com platform-api.sharethis.com *.twitter.com *.googletagmanager.com tagmanager.google.com *.google-analytics.com www.google-analytics.com *.g.doubleclick.net googleads.g.doubleclick.net *.googlesyndication.com *.googleadservices.com *.google.com cdn.jsdelivr.net www.youtube.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' blob: *.globalreach.com analytics.globalreach.com *.authorize.net *.stripe.com lib.paymentjs.firstdata.com *.paypalobjects.com www.paypalobjects.com *.googleapis.com code.jquery.com www.facebook.com connect.facebook.net ct.pinterest.com s.pinimg.com *.sharethis.com platform-api.sharethis.com *.googletagmanager.com www.googletagmanager.- strict-transport-security
max-age=31536000; includeSubDomains; preload;