ccli.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Nuxt
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
Third-party hosts loaded (2)
- static.cloudflareinsights.com×1
- www.googletagmanager.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1995-03-06
- Expires
- 2027-08-02 440 days left
- Updated
- 2025-08-02
- Name servers
-
- anna.ns.cloudflare.com
- gabe.ns.cloudflare.com
DNS records live
- NS
-
- anna.ns.cloudflare.com
- gabe.ns.cloudflare.com
- MX
-
- 0 ccli-com.mail.eo.outlook.com
- TXT
-
Show 12 TXT records
facebook-domain-verification=cvx960ktnwuunpgjpm525k7g1l79ematlassian-domain-verification=S2bVlvZrf4iWb/S6FLGHxf+BNjcn1yr1hwhnq+FnEHTcqRg6GAbEO+oroGtCieRosegment-site-verification=4tavmQKlqEh2QEhaBqIQVEs5RduBYDVcgoogle-site-verification=pAdp6bT98DNxe-ef-bFsLXnFRiXn_9JuyTjhBxjVyTs_0kvqumwayi09i4jn6no9xroy9a9ifs2apple-domain-verification=0E9tshjUL6SQmowYamazon-business-verification=78b7218fac5c22b55da83332faec61bc30a9f4e40e5941744b6b6280a4afb17a690v5dajckakcbkoeake5t5148google-site-verification=IPBr24bxmCCi9WVtTA7tZcwWfiLO36zWSl-f7GJLPq4google-site-verification=RsiWapVJlOtJ87vB9c4TdJBmdeijert5H8MwCOvTSMUgoogle-site-verification=WCLDaRg4Flg9ZCiuDoQ0sTE3GLjsa4kcxBV1tNfZrnkatlassian-sending-domain-verification=4f6ef7c7-61b5-45e9-bac7-c94e9eeabc01
Email authentication strong
- SPF
-
v=spf1 ip4:70.99.6.100 ip4:65.116.190.226 ip4:194.24.176.172 ip4:80.155.59.194 ip4:196.33.169.142 ip4:220.71.6.220 ip4:110.174.132.22 ip4:13.83.131.64 include:spf.protection.outlook.com include:servers.mcsv.net include:helpscoutemail.com include:_spf.atlassian.net include:spf1.ccli.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; ruf=mailto:starpraise-t@dmarc.report-uri.com; fo=1policy: reject (enforced) - DKIM
-
Show 5 DKIM selectors
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDnCrzmCfnWdqCHaHNQksHxK6mNU8I8F2qRQOe2Lmx1rYUP988kJD4GRrsBynX7weyHdb8xzNbCe0FjVW6we4… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - dkim:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDzpFrEAH9dbkLukLvwesHGWRDc+JCBkvzQYTpptOR+uz4brRd1V8VDPHPpQH7wRvNMhVh/LhTkPMBXtpJjeedqU2rfDl… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnaiWXB9oiFVDbOTpmAcwe2cdD9U2WS+C7uhF73J0UYvqPemFTe5bL4y8YeRcMu/NajxpMADqFkTGBQy1iO… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7z3icR6JPj558CXVLa/jYIBsJF0bDb6XUls1IOtEil4bpMYUPBC44CLiAFQYTkOgIQyPxxzzISMqY3EFqf…
selectors probed - selector2:
Certificate (current)
WE1
Expires in 41 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), display-capture=(), fullscreen=(self "https://songselectvue.dev.ccli.com:5175" "https://songselect.staging.ccli.com" "https://songselect.qa.ccli.com" "https://songselectvue.dev.ccli.com" "https://songselect.ccli.com"), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; font-src 'self' https: data:; form-action 'self' songselect.ccli.com; frame-ancestors 'self' *.ccli.com:5175 *.ccli.com rehearse-app-preview.starpraise.workers.dev; img-src 'self' data: *.cloudfront.net ccli.com *.ccli.com *.googletagmanager.com *.facebook.com *.clarity.ms *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.com *.bing.com *.hotjar.com *.hotjar.io *.cookiebot.com *.vimeocdn.com cclicomstrapiuploads.blob.core.windows.net; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; script-src 'self' https: 'unsafe-inline' 'strict-dynamic' 'nonce-5Y1m3l5+JKezOt+HwJXDfw12' *.cloudfront.net ccli.com *.ccli.com ajax.cloudflare.com *.cookiebot.com *.googletagmanager.com *.facebook.com *.clarity.ms static.cloudflareinsights.com *.hotjar.com *.hotjar.io; upgrade-insecure-requests;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin