bracedigital.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- www.google.com×2
- www.googletagmanager.com×2
- cdn-cookieyes.com×1
- unpkg.com×1
Social
Contact
- Phone
Registration
- Registrar
- 123-Reg Limited
- Created
- 2016-01-12
- Expires
- 2027-01-12 222 days left
- Updated
- 2026-01-13
- Name servers
-
- fred.ns.cloudflare.com
- jill.ns.cloudflare.com
DNS records live
- NS
-
- fred.ns.cloudflare.com
- jill.ns.cloudflare.com
- MX
-
- 1 bracedigital-com.mail.protection.outlook.com
- Verified for
-
- Brevo
- Google Workspace
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:45.131.138.126 ip4:45.131.138.205 -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.emailpolicy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
WE1
Expires in 77 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SameOrigin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; frame-ancestors 'self';script-src 'nonce-pcDAsW8ElWo2gjSfFKpUVQ==' 'self' *.hsforms.net *.jquery.com cdnjs.cloudflare.com d.adroll.mgr.consensu.org cdn.cookielaw.org cdn.cookielaw.org www.google-analytics.com *.googleapis.com www.googleadservices.com www.youtube.com *.google.com www.googletagmanager.com connect.facebook.net www.gstatic.com use.typekit.net www.google.com platform.twitter.com assets.pinterest.com log.pinterest.com vimeo.com connect.facebook.net pi-live.sagepay.com pi-test.sagepay.com tracking1.force24.co.uk *.adroll.com *.doubleclick.net unpkg.com ajax.aspnetcdn.com *.typekit.net *.cookieyes.com cdn-cookieyes.com; script-src-elem 'self' 'unsafe-inline' *.cookieyes.com cdn-cookieyes.com unpkg.com www.google.com cdnjs.cloudflare.com *.gstatic.com use.typekit.net; style-src 'self' 'unsafe-inline' *.googleapis.com maxcdn.bootstrapcdn.com *.jquery.com cdnjs.cloudflare.com; img-src 'self' data: img.youtube.com *.hsforms.com csi.gstatic.com- strict-transport-security
max-age=15768000; includeSubDomains; preload