calik.com
HTML metadata
Technology
- Server
- volt-adc
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- cdn-01.welcomingweb.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2000-04-18
- Expires
- 2032-04-18 2160 days left
- Updated
- 2023-04-10
- Name servers
-
- lars.ns.cloudflare.com
- rachel.ns.cloudflare.com
DNS records live
- NS
-
- lars.ns.cloudflare.com
- rachel.ns.cloudflare.com
- MX
-
- 10 calik-com.mail.protection.outlook.com
- TXT
-
Show 11 TXT records
openai-domain-verification=dv-xEngFuXbZ6WmkRQEqBECtUqarsdRktoOvDv9yP6N4OaK2/r95X6YrGzPlvP2Sv2mOGBZ9ZwTU6SLuNrr5bGpVCFV7TNj2ssdOOIN4wv7oDnERg==successfactors-site-verification=MjZkMTcyNjYxZmZkOGZiNDg3ZDJmZjU3YjViNTdmOGMxMjk3MDllY2YzMWQ2ZWVmNDdjODJhMmNhMjljNTc2OQ==5md47985hlc8e7knrcngeepnd161q5d0lkvu3f0t1l3epb74vs20Foxit-domain-verification=3eb5cf0771d8faf97e193b016cbf69a3MS=ms83608802apple-domain-verification=9tendKFn9qVE9dBqca3-e028d2335d514f00a9cf1d5789c5b204heyhack-verification=019c6fa8-af72-741b-a41c-5da9cf34ea50m876afuhpq9ailhhtg7lrfjfsc
Email authentication partial
- SPF
-
v=spf1 a mx ip4:91.216.91.0/24 ip4:176.235.153.10 include:spf.protection.outlook.com include:_spf-dc57.sapsf.eu -allstrict (-all) - DMARC
-
v=DMARC1; p=none; sp=none; rua=mailto:dmarcreport@calik.com; ruf=mailto:dmarcreport@calik.com; rf=afrf; pct=100; ri=86400policy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVkPXFO9CMDlgMkIzPFUYbVY2mVzZjGEfme///e1ooVh+jQU56vZIjPvlmhJppSE3oZ1qbQT1vkd4gwVgT30… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx0ewEX7FDSx+o6qQNJuqaY1H68Pp/nkX7t/MfInCsNPta+0twWhJp8KCYMIRFLKbSAM4yDCrcvAKru…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 204 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
Header values
- referrer-policy
same-origin, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
camera=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; connect-src *; font-src * data:; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; frame-ancestors 'none';, default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.clarity.ms https://scripts.clarity.ms https://cdn-01.welcomingweb.com https://dn-01.welcomingweb.com https://www.google.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com https://api.welcomingweb.com https://www.clarity.ms https://w.clarity.ms https://api.cookiespool.com; img-src 'self' data: https: http:; frame-src https://www.google.com; frame-ancestors 'self';- strict-transport-security
max-age=31536000