boh.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Cookie consent
-
- OneTrust
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (6)
- assets.adobedtm.com×1
- cdn.cookielaw.org×1
- cdn.timetrade.com×1
- d21y75miwcfqoq.cloudfront.net×1
- use.typekit.net×1
- www.google.com×1
Social
Contact
- Phone
- Address
- 111 S King St, 96813, Honolulu, HI, US
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1995-08-07
- Expires
- 2034-08-06 3001 days left
- Updated
- 2024-08-06
- Name servers
-
- ns.boh.com
- ns2.boh.com
- ns3.boh.com
- ns4.boh.com
DNS records
- MX
-
- 10 v-smtp1a-prd.boh.com
- 10 v-smtp1b-prd.boh.com
- 20 v-smtp1c-prd.boh.com
- TXT
-
Show 9 TXT records
atlassian-domain-verification=kfp9kW/JBrcGy6HieDNch2+bWmnNX+qQfGGtrbU2BdBnK6pNwtjb4Dzb9EfVjYJCMS=ms93838199google-site-verification=PKqR1BHhUP9uPBqDlczouoglD-J003dt4NoEpMHtWgEmiro-verification=20b847b7b51f5955ff5b06540af868440432438dcisco-ci-domain-verification=cb86406239b1a710ada6c8144f1f4057d998c8443c71708b904b3363794adbcdocusign=18bdb328-9b23-4fa9-bf4c-6e1019b3f098onetrust-domain-verification=ab463a0c2cde4886801b886481671070atlassian-domain-verification=NpSYk6/HANbvu7JJ8uBpDVku/CANTqypGI/SX2t21wqjWXjkYQTjt4qa6iF0anNfadobe-idp-site-verification=cbd26ab50bb6cf3a42153426d8f945c7f4a481d66ec8ba84ac27d903c9181750
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GeoTrust EV RSA CA G2
Expires in 170 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://*.boh.com; default-src https: https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com 'unsafe-inline'; img-src * 'self' data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' *- strict-transport-security
max-age=31536000- cross-origin-opener-policy
same-origin