churchstaffing.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Ads
-
- Meta Pixel
Third-party hosts loaded (5)
- 9d5b3ea504be47ae8beda530938b120f.js.ubembed.com×1
- connect.facebook.net×1
- salemchurchproducts.s3.amazonaws.com×1
- widget.freshworks.com×1
- www.googletagmanager.com×1
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 1999-04-19
- Expires
- 2030-04-19 1431 days left
- Updated
- 2020-07-01
- Name servers
-
- ns-cloud-e1.googledomains.com
- ns-cloud-e2.googledomains.com
- ns-cloud-e3.googledomains.com
- ns-cloud-e4.googledomains.com
DNS records live
- NS
-
- ns-cloud-e1.googledomains.com
- ns-cloud-e2.googledomains.com
- ns-cloud-e3.googledomains.com
- ns-cloud-e4.googledomains.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
Show 4 TXT records
amazonses:U23FOwgdSASsFpz4M3v3/7Hj+I9Qr3hN8+V0Y/wODWk=google-site-verification=8zibqzH-ztts3cC562-cDpYcv7V7jH7jqLt5YQtfqZAstripe-verification=8314c35dec01d7a74d79ef08ac3d85c07bbcff95214944f3920a3454314883b0google-site-verification=4siZ7FmhmiPSWIOOdgK1vxIJyMzKDwWPT3sv8EWidTo
Email authentication partial
- SPF
-
v=spf1 mx ip4:96.46.138.104/29 include:emsd1.com include:_spf.sparkpostmail.com include:email.freshdesk.com include:_spf.google.com include:spf.mandrillapp.com include:mailgun.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: wss: *; script-src * 'unsafe-inline' 'unsafe-eval' blob: data: *; img-src * 'unsafe-inline' 'unsafe-eval' data: *; frame-src * 'unsafe-inline' 'unsafe-eval' data: *; style-src * 'unsafe-inline' 'unsafe-eval' data: *- strict-transport-security
max-age=31622400; includeSubDomains; preload