bracbank.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- brackweb.s3.ap-southeast-1.amazonaws.com×44
- www.googletagmanager.com×4
- www.facebook.com×1
Social
Registration
- Registrar
- OnlineNIC, Inc.
- Created
- 2000-01-23
- Expires
- 2031-01-23 1710 days left
- Updated
- 2026-05-03
- Name servers
-
- lorna.ns.cloudflare.com
- peyton.ns.cloudflare.com
DNS records live
- NS
-
- lorna.ns.cloudflare.com
- peyton.ns.cloudflare.com
- MX
-
- 5 esecgw.bracbank.com
- TXT
-
Show 11 TXT records
google-site-verification=9BvZZd1Lh0sgMY25zJi-oIDJQFmKuhu99k_fUBGMF5Egoogle-site-verification=QxyaYwp-YakDcPcsxhEzAwnMPHtfhdmwm4vN3sG_kKogoogle-site-verification=vp-w3Exc9NmWZqiM_oxa55qIKMP-crqFeBp7fZR6TMs2tj4xpvwfyrxw79m3h4b9kw5x11dychb5wymz2lry84x44gcl29hc4m97hg206xs7AoSASqEI0yh6zQ2Tlgf7INSjVIiiIOC6s4dI0EKfPgrVwy5HfUJmcLKXCjmkAvWAIpw8IrPRglm3CQ4znofrA==MS=ms19236127OFOJ5eBf7cjhbBgJXL25mAw01GB/Mm7zpigU3W4Fq6Fles+JdaXSRAenNnwdlqzkExEioD/wJih75l1l3JGwJg==_globalsign-domain-verification=7T-qG4LrYqClY6_tQ-3kFegcL-iZ0b-XWOizAAP8r7_globalsign-domain-verification=Ty_Nl1CYXxCNU5Cv_gnJU_uO0Gn2XblFK9NdJQ6Aukglobalsign-domain-verification=K5oXbyi1pApW2b6yQW7VEi9I3lF3wDaYAUSv7wrTkT
Email authentication strong
- SPF
-
v=spf1 mx a ip4:118.179.217.208 ip4:118.179.217.37 ip4:118.179.217.47 ip4:118.179.217.50 ip4:118.179.217.41 ip4:118.179.217.146 ip4:118.179.217.86 ip4:118.179.217.88 ip4:118.179.218.68 ip4:103.146.77.25 ip4:103.146.77.197 ip4:118.179.150.19 ip4:103.146.76.180 include:spf.protection.outlook.com include:spf_syx.invalidemail.com include:ncapp02.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@bracbank.com; ruf=mailto:dmarc@bracbank.com; fo=1; ri=86400policy: quarantine - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6ezZtioRyJuqcdZCb+93RylkubZkAPLyA5hU5mM3Ppi/mVZMLP8k0Exw1fH5qxSUXIhycU9zjzWiRv… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3V8ZPTE9mSRgvd34KC3iQ4p5o4fYa/PNdbuOrV2AjwMxmRzlz/wk9fH4iwB0evMIKbjozf16Lj02jT… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo16iI0yJSg9NX2muL4NAx9tH34bcYVvAhN2wzbTEYBk5zPCO8xfKed4P9kM4CtJHmXrGyRMBwB1s2gmQ1D… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQChI7PwUn9jf2RBB4Oe+wXkkKtJOxc5t+p2VfNPBD2mccO3IKEICvuLCrssYW4jBubw3qz4lxd/GK3Tuppc5Bc1Cm…
selectors probed - default:
Certificate (current)
Amazon RSA 2048 M04
Expires in 187 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=(self), interest-cohort=(), payment=(self), usb=(), magnetometer=(), gyroscope=(), accelerometer=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics.google.com/ https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com https://cdn.jsdelivr.net https://unpkg.com https://*.tawk.to https://embed.tawk.to https://va.tawk.to https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://googleads.g.doubleclick.net https://www.google.com https://www.youtube.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.tawk.to; img-src 'self' data: blob: https:;; font-src 'self' data: http: https://fonts.gstatic.com https://*.tawk.to https://*.bracbank.com ; connect-src 'self' https://analytics.google.com/ https://brac-backend.singularitybd.net https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net/npm/antd/dist/antd.min.css.map https://maps.googleapis.com https://*.bracbank.com https://devapi.bracbank.com:- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin