carnegroup.com
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×2
- js-eu1.hs-scripts.com×1
Social
Registration
- Registrar
- Register SPA
- Created
- 2004-01-22
- Expires
- 2029-01-22 978 days left
- Updated
- 2026-05-08
- Name servers
-
- ns0.reg365.net
- ns1.reg365.net
- ns2.reg365.net
DNS records live
- NS
-
- ns0.reg365.net
- ns1.reg365.net
- ns2.reg365.net
- MX
-
- 30 carnegroup-com.mail.protection.outlook.com
- TXT
-
Show 18 TXT records
atlassian-domain-verification=glZ/VSfwLLt83JcuHZ/YO0cFVmooXfPEMaOiE93OLDkGefSHfH8bA0qjLEe/3/OWonetrust-domain-verification=8c961dab258640428ff067684622d2b946us75lbeenvhk3406gm1pgip3ibmid=e45b8f38-97a9-4c40-9695-4d97928ededbdblfk9bmhni7tlc6h0olv0lfjpfprep3bh34cfdcoubnvvb08k620019cb7b3130e097cbcda1153773486087faa55ds84dwy52mzzqg1lz0xgjl40snk0hcdb6MS=ms64799365docusign=d74c0538-5f78-4074-b882-b990cf404975JqqQjzp/gtHZs4tfHzWYg6z9RdocR5qfdTqrVR8jqaCD47gpxcKUILoil2xN3f3WpjtOHGAlaHquKDc5/ZuQww==intacct-esk=F34016B645C80934E0533A06410AE79Capple-domain-verification=a3ULbUMZ0aEdL395selector1-carnegroup-com._domainkey.CarneGroupltd.onmicrosoft.comn5ved6e74ep44e4hc192cjgmmewBRcVv8ffILA7/8eA2vAs3RZtJHvtvkcCDCsXAWF5Y2MokkBqkawIslYDQqjWyBNkCjOJvK4INF8iV/mqLNY8Q==nitro-verification-code=LTUxMjY2ODM3MTkyNTQ1NjkyMzU=h1os3n5ah6sof8mal9kafdti3q
Email authentication strong
- SPF
-
v=spf1 mx ip4:209.202.128.38 ip4:40.127.137.63 ip4:204.15.171.6 ip4:72.85.155.85 ip4:198.37.153.11 ip4:194.124.5.144 ip4:212.2.165.162 ip4:81.17.245.217 include:spf.newsletter.ie include:spf.protection.outlook.com include:sparkpostmail.com include:servers.mcsv.net include:_spf.salesforce.com include:_spf.intacct.com include:139842026.spf06.hubspotemail.net -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; fo=1policy: quarantine - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCy141urQqHJ9A7VjBi9QpEQilPTzCTFNoO7CbBvJ8OhH3vtLBmMARrugSzV7hVz4btjvosMQZ05jxtA0eOHu… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - dkim:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+y7n+lBsfp3+7pVffifpk1C3cqRwAjH153QBcHdyPBlApKGD/5PPS9zzbUO5w3sKiiBLq4oJZXBACyPiQcaff5uDg6… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqFaxzBD3FYZbvpUkd8wzRZrcWgD7IrzXmDOjY8iB4zQizNBttlpT3beJlag8rnkOUq1Vdz47FQVdS3noGm… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArB7vU9Ohpx/3sSTFGmexzVDkMHSvf6vXl9uIkKSZZeQzeTtSCGxIfzArO4rPN0VyZXSEV3ei+exRApOQ0r…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 176 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; img-src 'self' data: https://px.ads.linkedin.com https://www.carnegroup.com https://cdn.cookielaw.org https://*.hubspot.com https://*.hsforms.com https://*.hsforms.com https://i.vimeocdn.com; font-src 'self' https: data:; style-src 'self' https: 'unsafe-inline'; script-src 'sha256-nnBq/ahm+Z8Aa4YTqBVN6IOAY1RDi/Ue4/ReUV/UZVo=' 'nonce-S0Lm9XCOAwyhSjW53VYRbQ==' 'self' 'self' https://cdn.cookielaw.org https://snap.licdn.com https://js.monitor.azure.com https://*.hs-scripts.com https://*.hubspot.com https://*.hs-banner.com https://*.hs-analytics.net https://*.hscollectedforms.net https://*.hsadspixel.net https://*.hsforms.com https://www.google.com https://www.recaptcha.net; connect-src 'self' https://*.applicationinsights.azure.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://vimeo.com https://www.carnegroup.com https://static.hsappstatic.net https://*.hsappstatic.net https://*.hscollected- strict-transport-security
max-age=31536000; includeSubDomains;