castingabout.com
HTML metadata
Technology
- CMS
- Ghost
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (3)
- fonts.googleapis.com×1
- www.googletagmanager.com×1
- www.youtube.com×1
Social
Contact
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2004-01-15
- Expires
- 2031-01-23 1709 days left
- Updated
- 2023-04-07
- Name servers
-
- ns-1207.awsdns-22.org
- ns-1892.awsdns-44.co.uk
- ns-205.awsdns-25.com
- ns-525.awsdns-01.net
DNS records
Email authentication strong
- SPF
-
v=spf1 redirect=_spf.nonfatmedia.comno all qualifier - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@nonfatmedia.com!10m; ruf=mailto:dmarc@nonfatmedia.com!10m; rf=afrf; pct=100; ri=86400policy: reject (enforced) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1DeeYdAdIv8/YpML7+6+raVgArXOeoVq2BlS5Oa96CgedPrEh6SFsaBPDquBb3/hhVX1kGFmUkfTag8+72… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6nPUsB6EXR75zD1g3XY0/+kC9gi0xMf8JGXfzd0nyocFZBPvthBCZQJlZgXfotuUExyAQOl4vVZpi1/BUXvYOaT…
selectors probed - s1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 269 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
img-src * 'self' data: https://www.google-analytics.com https://www.googletagmanager.com https://i.ytimg.com; object-src 'self'; frame-src 'self' https://www.youtube.com https://www.google.com https://www.google-analytics.com https://www.googletagmanager.com; frame-ancestors 'self';- strict-transport-security
max-age=63072000; includeSubDomains