carotrans.com
HTML metadata
Technology
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×4
- ajax.googleapis.com×1
- js.hcaptcha.com×1
Social
Registration
- Registrar
- Netregistry Wholesale Pty Ltd
- Created
- 1996-06-21
- Expires
- 2030-06-20 1493 days left
- Updated
- 2025-04-16
- Name servers
-
- ns1.mitdps.net
- ns2.mitdps.net
- ns3.mitdps.net
DNS records live
- NS
-
- ns1.mitdps.net
- ns2.mitdps.net
- ns3.mitdps.net
- MX
-
- 10 au-smtp-inbound-1.mimecast.com
- 10 au-smtp-inbound-2.mimecast.com
- TXT
-
Show 14 TXT records
google-site-verification=sHvGuwAsZLKKSw0zoOLGDgg9qdE4qUu9kVk-qppD-5gglobalsign-domain-verification=C14AA3FFD50B68AA46BA703DC2834DCFglobalsign-domain-verification=43894195916446ED5659316909B44EF7globalsign-domain-verification=B570F4391D2217E30A6D67B44A38FD25globalsign-domain-verification=CF1DDF8030E5D9B98D79029C53246366globalsign-domain-verification=3F3DC755215CB38B21475AA0D57AE64Fglobalsign-domain-verification=EE774B1A1B5F609969261FE1804B2800qase-65d88edfec93441816a2be8cedd1fa9d64fe73e4knowbe4-site-verification=71f82e40aa8797fd06e4e1cfc73c726bgoogle-site-verification=Ou7Q5OYrUc-9T4Mijn9pou69x--ffDNBGZKPPMci97g_gzdtr4ipx1m059bn9jmwjigodrqji1hcisco-ci-domain-verification=a8a7f794ffe27c13ffdc4013a8a4e40350219af7c5d014fb5fbb75683e4b2adwkxzhhc.impervadns.net_wy0gb2a6swimxn1hr3nif4zy62axvhf
Email authentication strong
- SPF
-
v=spf1 ip4:64.7.120.69 ip4:13.88.113.130 ip4:13.88.116.145 include:au._netblocks.mimecast.com include:_phishspf.knowbe4.com include:spf-cwip.mainfreight.com include:servers.mcsv.net include:spf.constantcontact.com include:amazonses.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:e2f9eecd6282019@rep.dmarcanalyzer.com; ruf=mailto:e2f9eecd6282019@for.dmarcanalyzer.com; fo=1;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 297 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
autoplay=(),camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=*, publickey-credentials-get=*, screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=*, clipboard-write=*, hid=*, idle-detection=*, serial=*, window-placement=*- x-content-type-options
nosniff- content-security-policy
base-uri 'self';default-src 'self';script-src 'nonce-e89f9aee77d74ce9bd062976ea69d911' 'strict-dynamic';style-src 'self' https: fonts.googleapis.com https://*.helpfruit.com https://*.faqbot.nz 'unsafe-inline';img-src 'self' data: https://maps.gstatic.com https://maps.googleapis.com https://mapsresources-pa.googleapis.com https://i.vimeocdn.com https://uat.mainfreight.com https://uat.chemcouriers.com https://uat.dailyfreight.co.nz https://uat.owens.co.nz https://uat.carotrans.com https://*.mainfreight.com https://*.carotrans.com https://www.google.com;connect-src 'self' https://maps.googleapis.com https://www.google.com https://www.google-analytics.com https://www.facebook.com/tr/ data:;font-src 'self' https://*.helpfruit.com https://*.faqbot.nz data: https: fonts.gstatic.com;frame-src https://newassets.hcaptcha.com https://player.vimeo.com https://www.googletagmanager.com;frame-ancestors 'none';- strict-transport-security
max-age=31536000