bgc-salem.org
HTML metadata
Technology
- Server
- Apache
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- translate.googleapis.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- Street NESalem, OR 97301
Registration
- Registrar
- Network Solutions, LLC
- Created
- 2000-01-11
- Expires
- 2028-01-11 601 days left
- Updated
- 2024-01-14
- Name servers
-
- ns17.worldnic.com
- ns18.worldnic.com
DNS records live
- NS
-
- ns17.worldnic.com
- ns18.worldnic.com
- MX
-
- 1 smtp.google.com
- TXT
-
Show 4 TXT records
google-site-verification=InWaPUF8Z4stu4HMo_1P6WXTnCtyyvCFK_3P_I30jSogoogle-site-verification=X1qrHYfAPd6HztPyf__JgALEzDw4XvqUafIAiGt-qIofacebook-domain-verification=yu8jkktiw2is225p1rmmmm4uceuhyi1lkg3tpr64iem194edfqgt0nlh
Email authentication weak
- SPF
-
v=spf1 include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyyejGdOMdovxcD/ZyZIFc+/23ad Ol8fl8obEm4vNsxxRvEjWevm43l9YJcB2M2zuhI5+ri1HUbFkV…
selectors probed - google:
Certificate (current)
R12
Expires in 60 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), camera=(), microphone=(), interest-cohort=(), ch-ua-full-version-list=()- x-content-type-options
nosniff- content-security-policy
default-src https: 'self' bgc-salem.org cdn.bgc-salem.org *.google-analytics.com *.youtube.com *.youtube-nocookie.com *.facebook.com; base-uri 'self'; frame-ancestors 'self' https://bgc-salem.org https://bgc-salem.com ; script-src bgc-salem.org bgbingo.org www.googletagmanager.com cse.google.com ajax.googleapis.com www.gstatic.com www.google.com translate.google.com translate.googleapis.com translate-pa.googleapis.com widgets.uniteus.io visitor.constantcontact.com static.ctctcdn.com 'unsafe-inline' 'unsafe-eval'; style-src https: 'self' 'unsafe-inline'; object-src 'none'; img-src https: data: bgc-salem.org cdn.bgc-salem.org; form-action 'self' visitor.constantcontact.com; upgrade-insecure-requests;- strict-transport-security
max-age=63072000; includeSubDomains; preload