bombpop.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- wellscdn.com×28
- cdnjs.cloudflare.com×4
- cdn.jsdelivr.net×2
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1995-12-02
- Expires
- 2027-02-01 257 days left
- Updated
- 2026-02-01
- Name servers
-
- brad.ns.cloudflare.com
- jill.ns.cloudflare.com
DNS records live
- NS
-
- brad.ns.cloudflare.com
- jill.ns.cloudflare.com
- MX
-
- 10 bombpop-com.mail.protection.outlook.com
- TXT
-
google-site-verification=dcei-kIrZAme6A2zOzSq-Ak3X5hSVln6WvrRYwWpMtY
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDROEMSA3/a3z557WJrE6JVBDrsGlrlxVM79oJZos9/23xiLwbiEVEv52rZA2EOJMres5JHas3kWpMr7CV+23… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+ELs45/6xFZS7pcguWN1xP0v/PI2c7iqKGJ8UHKmVx18RIk/NKV3SEZ0UAblQ5UDtG3UMbyxvCq4B7D6zy… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDxCD6cGIumV5GBa83UbmGfjCU3Z+a/r98tbrLHUmlyeAMUU29Ll4ggVeJN/O3/laUxTOFfnIkaCDP/GX7/z0iRTU…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 36 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), autoplay=(), camera=(), display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(self "https://wellscdn.com" "https://destinilocators.com"), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' https://bat.bing.com https://analytics.tiktok.com https://*.applicationinsights.azure.com https://*.snapchat.com https://sc-static.net https://*.doubleclick.net https://*.g.doubleclick.net https://*.google.com https://www.googleadservices.com https://*.bazaarvoice.com https://*.googlesyndication.com https://*.google-analytics.com https://*.tiktokw.us https://*.facebook.com https://*.googletagmanager.com https://*.monitor.azure.com https://*.cdn.applicationinsights.io; font-src 'self' https://wellscdn.com https://fonts.googleapis.com https://fonts.gstatic.com https://use.typekit.net; frame-src 'self' https://www.youtube.com https://www.googletagmanager.com https://*.doubleclick.net https://destinilocators.com https://www.google.com https://iframe-mdm.bombpop.com https://*.snapchat.com; img-src 'self' https://wellscdn.com https://bat.ping.com https://*.doubleclick.net data: https://*.bazaarvoice.com https://bat.bing.com https://*.google.com https://- strict-transport-security
max-age=2592000