clickpay.com
HTML metadata
Technology
- CDN
- Akamai
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×2
- ajax.googleapis.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2010-01-23
- Expires
- 2028-01-23 614 days left
- Updated
- 2026-01-24
- Name servers
-
- rpns1.realpage.com
- rpns2.realpage.com
- rpns3.realpage.com
- rpns4.realpage.com
DNS records live
- NS
-
- rpns1.realpage.com
- rpns2.realpage.com
- rpns3.realpage.com
- rpns4.realpage.com
- MX
-
- 10 realpage-com.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
jQj74kFNqNr2DdI8t4/ohnWlGNW3lL56FyNx50NYiGfQS0H1ohgCYvaQPdNfCcxx+0rB0QL/b52icB44PNnc8Q==pardot703303=67e68cfef7574b372edbbbcfbf6b75e674a94e28e8955826af490d970995b31epardot703303=a4545a2d554690ce88806523629e7917e92e684aa9ef838163dd1845043a7b53pardot_265342_*=64d454fdba5724fe07ab511d7488bad7280e0aa4d1162f95b60aab96a51b5d22rovag_verification_token=2343217E54DF4F4DB144D79DE2C0734Fgoogle-site-verification=i-Y3mWt9et6ISvil6ErTSz3nAvFMZnnFt6YdMjVU_eU
Email authentication strong
- SPF
-
v=spf1 include:_spf3.clickpay.com include:_spf4.clickpay.com include:spf.mandrillapp.com include:_spf.salesforce.com include:spf.smtp2go.com include:et._spf.pardot.com include:spf.protection.outlook.com include:mail.zendesk.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:dmarc_reporting@realpage.com,mailto:itnotify@clickpay.com;ruf=mailto:dmarc_reporting@realpage.com;fo=1;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtt52jKBDX0B+aNgvz8cmGUtaFjvaZz5I2izUSQrzbGKCPhQv5WSrNA8r5M0ZfN1Jav0xneQf8u3v9X… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvqJBpfLMOF6tLpcTjJh6fKcFUOy95xa2nD28JOEk8K9Z88YyMAgVuTZVZ3bcIVGaIp1c188S7LP5l1WJ59… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC2Ah3vMcVUXA1b229Ax+/8vPLd6YgGeZLEyIxOE0IAvEU3trmC018isokPZ5QlPcU1rIYSmGZcSNSfaU7nCBZirq…
selectors probed - selector1:
Certificate (current)
DigiCert Global G3 TLS ECC SHA384 2020 CA1
Expires in 133 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://*.akamaihd.net https://bam.nr-data.net https://*.newrelic.com https://www.surveymonkey.com https://c.bing.com https://*.my.site.com https://*.lightning.force.com https://*.salesforceliveagent.com https://*.akstat.io https://*.my.salesforce.com https://*.onetrust.com https://seal.godaddy.com https://*.clarity.ms https://*.doubleclick.net https://snap.licdn.com https://*.linkedin.com https://*.google.com https://*.gstatic.com https://*.googleadservices.com https://*.clickpay.com https://*.novelpay.com https://*.cookiepro.com https://*.cookielaw.org https://*.go-mpulse.net https://*.googleapis.com https://*.google-analytics.com https://*.googletagmanager.com https://cdnjs.cloudflare.com https://*.my.salesforce-scrt.com ; frame-ancestors 'self';- strict-transport-security
max-age=63072000; includeSubDomains; preload