civica.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- ajax.googleapis.com×1
- dc.ads.linkedin.com×1
- dl.episerver.net×1
- use.typekit.net×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Total Web Solutions Limited
- Created
- 1998-12-18
- Expires
- 2028-12-18 944 days left
- Updated
- 2024-12-03
- Name servers
-
- ns1-09.azure-dns.com
- ns2-09.azure-dns.net
- ns3-09.azure-dns.org
- ns4-09.azure-dns.info
DNS records live
- NS
-
- ns1-09.azure-dns.com
- ns2-09.azure-dns.net
- ns3-09.azure-dns.org
- ns4-09.azure-dns.info
- MX
-
- 10 mx10.civica.com
- 20 mx20.civica.com
- TXT
-
Show 19 TXT records
ds5c1hrgpwjp2tv4xvtpsdztlm8j1j3bnotion-domain-verification=oqm5B30FTIMBPkLujz0Gcv4jEJ83Zh4qwpi9L0VYDyt_7gbemmhil6v4cms7c231ejfd7mjvsp0h13dgzwtl1y773whw99wdzkkh2jxryz7apple-domain-verification=Dl4JR7JWjYN8Vrtfgoogle-site-verification=zNfUSaeXtuT6SBs1EN-6Ewo7Hol974JCzX43h3cox5c9n8zpxmst80pd2pv54cqggcncwmykqd8onetrust-domain-verification=f91a5e3499e947f481063c5ba9668290onetrust-domain-verification=194f88b41ba145c9b6e712ec32d35e09FKZ+o423hMWi9CzVW9iltJxwjcT7NWAEC2JOl9FQ+B1Sk7/toYTTYIAYl1MQvr+F+j3o8IaiifGEZLHlAc6cCw==docker-verification=bb36b0fb-ef1b-46a4-afa3-1f9dc7f2bfceapple-domain-verification=3xCGLztWZmhbQOY3_er1qnru49nyp1afd776zuz0oahfa4p8anthropic-domain-verification-4w4t5r=CVISRlG29NuaQVvELVTPb9sblslack-domain-verification=caxjgDzjrIITWeuWqQcOSXjLzOxVIAkfNZZb0xHerrxgkjhyzkp9nm1b5khqk903c6r5vtjbatlassian-domain-verification=Ty0pNJbtlWLmhI8VqN5sillOMKd4BcpOB+0/KPmvnl0r80rd1rjJM9Pxq4+r4O1osqwjiuRgvzNcb+rywj/pMmyG8c72kLlWg2KemFkQ9MzyMPfgdcTjElFxo7sdBx5/dQVzf58zIo9vR68MRXOPjw==MS=ms34512714
Email authentication strong
- SPF
-
v=spf1 include:spf-uk.emailsignatures365.com include:spf.protection.outlook.com include:_spf.salesforce.com ip4:213.143.146.147/32 ip4:213.143.144.115/32 ip4:213.143.146.144/32 ip4:213.143.144.112/32 ip4:203.56.2.222/32 ip4:103.88.181.10/32 ip4:103.15.73.167/32 ip4:203.56.2.61/32 ip4:175.45.118.232/32 ip4:49.255.239.40/32 ip4:20.254.99.188/32 ip4:20.254.100.16/32 ip4:20.0.254.77/32 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; ruf=mailto:dmarc.forensics@civica.com; rua=mailto:dmarc.reports@civica.com; adkim=r; aspf=r; fo=1policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDtWhInUXzGI6VyCefOXUxK+wdHwBAzZjx8SxsIEgEQpKfu2dq+2L3UR9io+xHVwC2uLhZ5MMKhTF8N6DRnd8… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6p8RLSUatgvXifWNkc9W3rneMy+3XhmOeWkUmYdmgaMxtQONPutOLEAwp+qBixhJL7OyvsSWmEDlfGI57rz…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 77 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self), microphone=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://www.google-analytics.com https://ajax.googleapis.com https://cdn-ukwest.onetrust.com https://img.en25.com https://connect.facebook.net https://use.typekit.net https://az416426.vo.msecnd.net https://www.civica.com https://snap.licdn.com https://cdnjs.cloudflare.com https://*.episerver.net https://www.youtube.com https://geolocation.onetrust.com/ https://s3121.t.eloqua.com https://cdn.tiny.cloud/ https://static.oktopost.com/ https://okt.to/ https://*.demandbase.com/ https://s2079104782.t.eloqua.com/ https://cdn.cookielaw.org/ https://*.hotjar.com https://js.monitor.azure.com/; connect-src 'self' https://*.onetrust.com https://*.visualstudio.com https://*.google-analytics.com https://stats.g.doubleclick.net https://s3121.t.eloqua.com https://civica-privacy.my.onetrust.com https://cookiesuksouth.blob.core.windows.net/ https://cdn.linkedin.oribi.io https://img.en25.com https://*.d- strict-transport-security
max-age=31536000; includeSubDomains; preload