bsmconsulting.com
HTML metadata
Technology
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×2
- code.jquery.com×1
- fonts.gstatic.com×1
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 1997-05-01
- Expires
- 2027-05-02 347 days left
- Updated
- 2025-11-25
- Name servers
-
- ali.ns.cloudflare.com
- joel.ns.cloudflare.com
DNS records live
- NS
-
- ali.ns.cloudflare.com
- joel.ns.cloudflare.com
- MX
-
- 0 bsmconsulting-com.mail.protection.outlook.com
- TXT
-
MS=ms41826135bonc5rsqdes4hhqp1ugu4h9hnd
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.us.exclaimer.net include:1863187.spf05.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1no policy tag - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuUmbWHjp5v9Za0aO9DWqhG4gcla4A0KG9ueHr7Aaq1RLLziMKscR8SfbXPlbwzovjlc1P00YwNblnJ…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 138 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://browser.sentry-cdn.com https://cdn.bsmconsulting.com https://cdn.spinxweb.net https://drul01liwqhrt.cloudfront.net https://cdn.cookielaw.org/ https://www.google.com/recaptcha/api.js https://cdnjs.cloudflare.com https://www.gstatic.com/recaptcha/ https://ajax.googleapis.com/ajax/libs/jquery/ https://ajax.googleapis.com/ajax/libs/angularjs/ https://maxcdn.bootstrapcdn.com/ https://cdn.ckeditor.com/ https://bsm-3.disqus.com https://c.disquscdn.com https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtm.js https://www.google-analytics.com/analytics.js https://launchpad-wrapper.privacymanager.io/ https://view.genial.ly/static/embed/embed.js https://statics-view.genial.ly/view/static/js/ https://e.infogram.com/js/dist/ https://sentry.io/api/ https://cse.google.com/ https://www.google.com/cse/ https://partner.googleadservices.com/gampad/ https://csp.withgoogle.com/csp/ https://launchpad.p- strict-transport-security
max-age=31536000