clarknuber.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (7)
- js.hsforms.net×3
- www.googletagmanager.com×2
- cdn.cookie-script.com×1
- cdnjs.cloudflare.com×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- player.vimeo.com×1
Social
Contact
- Phone
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 2000-03-04
- Expires
- 2027-03-04 289 days left
- Updated
- 2024-01-08
- Name servers
-
- ali.ns.cloudflare.com
- phil.ns.cloudflare.com
DNS records live
- NS
-
- ali.ns.cloudflare.com
- phil.ns.cloudflare.com
- MX
-
- 10 us-smtp-inbound-1.mimecast.com
- 10 us-smtp-inbound-2.mimecast.com
- TXT
-
Show 8 TXT records
atlassian-domain-verification=Ih1FAutQek3ThR2ireZ9tYQaufEM7vftadKy90kKk05oOc5SoP7ZS80EISFUJbNhcanva-site-verification=t6OKu49-LZeMDBa3JsuDNwintacct-esk=4FED1A5569DB986BE053E606A8C0AF49ka1k8t5ts9vhmne98javc696ifpandadoc-domain-verification=czRkby2LrDx8aXNtxKmikWremarkable-domain-verification=72593797-1824-444d-a999-d5cae9713cdaapple-domain-verification=TTyXxCE3vwqCDHcvoG8iT_oL7_BIYbK3Y8DcDQAZmDIasv=70b74f637c1a830facafd933076d68ef
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:us._netblocks.mimecast.com include:3898931.spf03.hubspotemail.net include:_spf.intacct.com include:spf.mtasv.net include:_spf.samanage.com ip4:149.72.147.186 ip4:167.89.101.239 ip4:168.245.40.44 ip4:142.0.180.120 ip4:173.0.80.0/20 ip4:66.211.168.0/22 ip4:4.7.16.128/26 ip4:38.108.186.0/24 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; sp=reject; fo=1; rua=mailto:xn4lhrhd@ag.dmarcian.com; ruf=mailto:xn4lhrhd@fr.dmarcian.compolicy: reject (enforced) · sp=reject - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuQaNBhe8w7yV4nuoBa0fAmjW3L82VMwsRowpxmegP8XdJbNC3mgqUyIehDe+FmkSLq6DlwZpIAuYTgNJfm… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDOu4xX41011tjZOswgWgysAkTlXF180Nk1icz6HOILrHsmXg0gFeTmnsNBU6dTP02Sbm2HAESruA4bd0SKuBaNZm…
selectors probed - s1:
Certificate (current)
R13
Expires in 49 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
deny- permissions-policy
accelerometer=(), autoplay=(self), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(self), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), hid=(), idle-detection=(), serial=(), window-placement=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://ajax.googleapis.com https://whova.com https://hb.wpmucdn.com https://js.hsforms.net https://www.googletagmanager.com https://cdn.cookie-script.com/ https://*.hsforms.com https://www.buzzsprout.com https://c0.wp.com/ https://*.hsappstatic.net https://kit.fontawesome.com; style-src 'self' fonts.googleapis.com 'unsafe-inline' https://js.hsforms.net https://c0.wp.com https://s0.wp.com https://hb.wpmucdn.com https://fonts.bunny.net https://cdnjs.cloudflare.com; font-src 'self' fonts.gstatic.com data: https://c0.wp.com https://s0.wp.com https://fonts.bunny.net https://hb.wpmucdn.com https://ka-f.fontawesome.com https://cdnjs.cloudflare.com; img-src 'self' https: data: b3205068.smushcdn.com https://*.hsforms.com https://*.hubspot.com https://www.googletagmanager.com; frame-src 'self' https://securityscorecard.com/ https://scores.securityscorecard.io/ https://whova.com https://player.vimeo.com https://js.hsforms.net https://*.hsform- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin; report-to="default"- cross-origin-resource-policy
same-origin