birdsonghearing.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- CMS
- Nuxt
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
- Fonts
-
- Adobe Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (6)
- images.prismic.io×7
- birdsong.cdn.prismic.io×4
- use.typekit.net×2
- consent.cookiebot.com×1
- player.vimeo.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2021-12-13
- Expires
- 2027-12-13 571 days left
- Updated
- 2025-12-14
- Name servers
-
- ns-1471.awsdns-55.org
- ns-1575.awsdns-04.co.uk
- ns-593.awsdns-10.net
- ns-66.awsdns-08.com
DNS records live
- NS
-
- ns-1471.awsdns-55.org
- ns-1575.awsdns-04.co.uk
- ns-593.awsdns-10.net
- ns-66.awsdns-08.com
- MX
-
- 10 birdsonghearing-com.mx1.arsmtp.com
- 20 birdsonghearing-com.mx2.arsmtp.com
- TXT
-
Show 7 TXT records
"v=spf1 ip4:216.46.126.4 ip4:216.46.107.32 ip4:204.246.133.170 include:spf.protection.outlook.com9zf92whbzqs7tcqm5dkw5zsc64q27mryinclude:birdsonghearing-com.spf.smtp25.com include:spf.safewebservices.com include:em4073.provider.birdsongheaing.com include:edgepilot.com -all"00DO200000GjWia=1TBO20000000UpJ3rbCpEhjZ7KblcS+zmRWMw==00D8c0000086zNL=1TBPj0000000EqzjBsUeS9af060Bq8BatpeVw==
- Verified for
-
- Adobe
- Atlassian
- Microsoft 365
- TeamViewer
Email authentication partial
- SPF
-
v=spf1 ip4:216.46.126.4 ip4:216.46.107.32 ip4:204.246.133.170 include:spf.protection.outlook.com include:spf.edgepilot.com include:birdsonghearing-com.spf.smtp25.com include:spf.safewebservices.com include:edgepilot.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxvhihNkqyIz6gbfNq+0gXNIdY96aSs/4wxEabBIBTXXXIqJPiaQrY7oa7Y9Q/uhV+XOLZS3fEllLqV…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 155 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'sha256-yqtA4Bv8qRojAvbmfNq4Aehg3g1HM4/5NvcM9SWU5+0=' 'sha256-U3cp1xiJVtUkTskXAxWWH+nMBDPds2XG5fEoippzjng=' 'sha256-i1EoV/MbiTNiWmASEmtvrsWZWiF0hDR/F7wBTeYGgLg=' 'sha256-j6UN294m1JvtqJo2jmbgu9yjXRTp4s1USKo1yIsrfUk=' 'sha256-IcnycNMbUH+v4hbTOc5XBQKi0a5yjaK9W3RfAZFRXCo=' https://consent.cookiebot.com https://cdn.curator.io https://static.cdn.prismic.io https://www.googletagmanager.com https://consentcdn.cookiebot.com https://*.google-analytics.com https://*.analytics.google.com https://snap.licdn.com https://d10lpsik1i8c69.cloudfront.net https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net https://cdn.curator.io; img-src 'self' data: https://*.prismic.io https://*.curator.io https://*.cookiebot.com https://imgsct.cookiebot.com https://*.google-analytics.com https://*.analytics.google.com https://*.linkedin.com https://*.facebook.com https://*.luckyorange.net; font-sr- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin