bongo4u.com
HTML metadata
Technology
- jQuery
- 1.7.1 known XSS (<3.5)
Third-party hosts loaded (1)
- common.emerge2.com×1
Contact
- Address
- Waterloo, ON, CA
DNS records live
- NS
-
- ns1.emerge2.com
- ns2.emerge2.net
- ns3.emerge2.net
- MX
-
Show 7 MX records
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- 30 aspmx4.googlemail.com
- 30 aspmx5.googlemail.com
- TXT
-
Emerge2 Digital Inc., emerge2.comBongo4U
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com include:_spfe2.emerge2.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:mqeetumld2@rua.powerdmarc.com; ruf=mailto:mqeetumld2@ruf.powerdmarc.com; pct=100; fo=0:1:d:s;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq6Ph+DGy16CnWE6be9zIdjYu6NfLfZmbQ+1uasvZvZp3/oSXFKfT6TrBL0Tygxb5yLmPWoAxEoXNZ5…
selectors probed - google:
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- missing Content Security Policy
Header values
- referrer-policy
origin, unsafe-url- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=(self)- x-content-type-options
nosniff- strict-transport-security
max-age=2592000- content-security-policy-report-only
default-src 'self' data: 'unsafe-inline' a.bongo4u.com; script-src 'self' data: 'unsafe-inline' a.bongo4u.com blob: 'unsafe-eval' bongo4u.com *.bongo4u.com *.emerge2.com *.google.com *.gstatic.com *.google-analytics.com *.googleapis.com *.googleusercontent.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com *.yahooapis.com *.mailchimp.com *.list-manage.com chimpstatic.com *.ipify.org jsonip.com *.amazonaws.com/downloads.mailchimp.com/ *.jquery.com *.hotjar.com acsbapp.com *.bootstrapcdn.com googleads.g.doubleclick.net *.elfsight.com *.createsend1.com *.roomvo.com; connect-src 'self' data: 'unsafe-inline' a.bongo4u.com comments.emerge2.com util.emerge2.com bongo4u.com *.emerge2.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.ca *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.doubleclick.net *.facebook.com *.hotjar.io *.hotjar.com acsbapp.com *.acsbapp.com *.elfsight.com createsend.com *