chelco.com
HTML metadata
Technology
- Server
- Sucuri
- CMS
- Drupal
- Fonts
-
- Font Awesome
- Google Fonts
Third-party hosts loaded (6)
- fonts.googleapis.com×4
- use.fontawesome.com×3
- acsbapp.com×1
- docs.google.com×1
- moderate.cleantalk.org×1
- tag.brandcdn.com×1
Social
Contact
- Phone
- Address
- rd based on data modeled by the ACSI®in 2023
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1996-10-08
- Expires
- 2030-10-07 1601 days left
- Updated
- 2020-10-07
- Name servers
-
- ns10.dnsmadeeasy.com
- ns11.dnsmadeeasy.com
- ns12.dnsmadeeasy.com
- ns13.dnsmadeeasy.com
- ns14.dnsmadeeasy.com
- ns15.dnsmadeeasy.com
DNS records live
- NS
-
- ns10.dnsmadeeasy.com
- ns11.dnsmadeeasy.com
- ns12.dnsmadeeasy.com
- ns13.dnsmadeeasy.com
- ns14.dnsmadeeasy.com
- ns15.dnsmadeeasy.com
- MX
-
- 10 chelco.com.1.0001.arsmtp.com
- 20 chelco.com.2.0001.arsmtp.com
- TXT
-
Show 5 TXT records
MS=D215E6BC4948E021CEDA3CEF56EAD3E5C4255E2Bt45ool2ngnmjs6hslopjolmv8jMS=01-05-2022 msverfdomMS=ms41875836apple-domain-verification=Jp29T2iGspNRR1ra
Email authentication partial
- SPF
-
v=spf1 include:_spf.smtp.com include:spf.mandrillapp.com include:edgepilot.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@chelco.com; ruf=mailto:dmarc@chelco.com; fo=1policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
Starfield Secure Certificate Authority - G2
Expires in 24 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://cdnjs.cloudflare.com https://acsbapp.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://polyfill.io https://unpkg.com https://use.fontawesome.com https://stackpath.bootstrapcdn.com https://www.googletagmanager.com https://www.google-analytics.com https://js-agent.newrelic.com https://www.google.com https://www.gstatic.com https://player.vimeo.com https://*.vimeocdn.com https://connect.facebook.net https://platform.twitter.com https://www.youtube.com https://*.upgrade.guide https://translate.google.com https://*.googleapis.com https://svc.webspellchecker.net https://touchstoneenergy.com https://cdn.questline.com https://weatherwidget.io https://cdn.gtranslate.net https://www.powr.io https://c03.apogee.net https://*.hrmdirect.com https://www.buzzsprout.com https://tag.brandcdn.com https://adservices.brandcdn.com https://*.cleantalk.org; object-src 'none'; style-src 'se- strict-transport-security
max-age=31536000; includeSubDomains; preload