cityofml.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- docaccess.com×1
- www.facebook.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2007-08-28
- Expires
- 2026-09-28 131 days left
- Updated
- 2025-09-29
- Name servers
-
- ns0.dnsmadeeasy.com
- ns1.dnsmadeeasy.com
- ns2.dnsmadeeasy.com
- ns3.dnsmadeeasy.com
- ns4.dnsmadeeasy.com
DNS records live
- NS
-
- ns0.dnsmadeeasy.com
- ns1.dnsmadeeasy.com
- ns2.dnsmadeeasy.com
- ns3.dnsmadeeasy.com
- ns4.dnsmadeeasy.com
- MX
-
- 0 mx-01-us-west-2.prod.hydra.sophos.com
- 1 mx-02-us-west-2.prod.hydra.sophos.com
- TXT
-
Show 10 TXT records
google-site-verification=pjCHHE3oMbXQOe2uz6HDqDKTW5MHXjng4jCQHnmNuawb39e1ec36e394fc1b80c472dc28bc601sophos-domain-verification=99d6b3b9e164b9a1a7b6fda968d57d3877dacb24bw=esErQAHfO5LuME6x2byWFc5M5HotFzu1Tgor5HK3VNtM21a191c8ca57a247c4406efa98fa3418e03d38fef573cdeaaflogmein-verification-code=67f5b093-d945-491f-83ec-b455bf0a7a17apple-domain-verification=y0UHDTiDjWHpIQ48sophos-domain-verification=670e05fdee84724bb3f5aabea02582d9507f23e7d0a4e89019f91a171bcc1d1bZOOM_verify_EnhGJ1jxT_KJq5bHWxiT6QDqDnSisYUoyfVJj4x6ADDSA/qqweGLsyHhgvR6nO+kPL6BsYU5/vFoxp//OZNwW2NLlV7HHzbzblVdpYy/so0A==
Email authentication strong
- SPF
-
v=spf1 include:_spf_uswest2.prod.hydra.sophos.com include:spf-westus.emailsignatures365.com include:spf.protection.outlook.com include:spf.constantcontact.com include:sendgrid.net include:emailus.freshservice.com a:xg.cityofml.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; fo=1; rua=mailto:1f311bfa@mxtoolbox.dmarc-report.com; ruf=mailto:1f311bfa@forensics.dmarc-report.compolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAy8INNU9AWQmWB69ePQOiPA1DdT/nafGrjLaCrxH6O1ST7cZ86npEZhYaJXvFBMe27yp6YdgsZRIB/U…
selectors probed - selector1:
Certificate (current)
R13
Expires in 39 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://*.granicus.com https://platform.civicplus.com https://account.civicplus.com https://analytics.civicplus.com; img-src * data: blob:; worker-src * data: blob: 'unsafe-eval' 'unsafe-inline'; script-src * about: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; media-src * blob:; font-src * data:; default-src *