communitywestbank.com

.com crawl

First seen 2026-04-16 · Last seen 2026-05-17 · ok HTTP/1.1 200 5556 ms crawled 2026-05-11

US · 20.119.16.51 · AS8075 Microsoft Corporation

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
Community West Bank | Home
Description
Discover secure personal & business banking with Community West Bank. Manage your finances & pay bills with ease. Join us today for reliable banking solutions
Language
en
Canonical
https://www.communitywestbank.com/

Open Graph

url
https://www.communitywestbank.com/
title
Community West Bank | Home
site name
Community West Bank
description
Discover secure personal & business banking with Community West Bank. Manage your finances & pay bills with ease. Join us today for reliable banking solutions

Technology

CDN
Azure Front Door
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.googleapis.com×2
  • fonts.gstatic.com×1
  • www.googletagmanager.com×1

Contact

Phone
Address
7100 N. Financial Drive, Suite 101, 93720, Fresno, CA

Registration

Registrar
GoDaddy.com, LLC
Created
2003-09-26
Expires
2026-09-26 128 days left
Updated
2024-09-27
Name servers
  • ns1.boitdns.com
  • ns2.boitdns.com
  • ns3.boitdns.com

DNS records live

NS
  • ns1.boitdns.com
  • ns2.boitdns.com
  • ns3.boitdns.com
MX
  • 10 all.secureyourmail.com
TXT
Show 6 TXT records
  • RU72L4TNxC6DRCPAUZL37ihtE0ioKcMF7afzF3/JlcSBhk3LV56BPu+1jR0EuQI9/YlScQ1MgVKRKzQtuxuhOg==
  • C+I9NpPEXpYbNzxozIArnztuZhqwmwxalpjwRRBwNsQaWsDj3gvVSWYQv2/QkXezkuzZXRSAhUPbIWL/Ep2YJg==
  • IsgBzc3x1uaCLqPykv4OjU8R/dCLscF4CAy5D1ZgHcqM32x0+xX1vMcTvXBVmt/HR3Sy4LTvxF5Y+UTl6yvWbg==
  • MnP3Uix1PYEbB509KpDqvI9eYOntNxQpP54Zz2qgQqeUjmznHMAfh09j4NpqMrCAWxmd7Vj+UyaJSdJ/e2NUhw==
  • wN2UTJfN+O3juVkt3kKYdAQ5/WzbXe+g58NqR/4mO8/obwyzb9t2CwiJuE2RyTwA0mD5lDgUO9yb/Y3l6wiECg==
  • Ia5abgJhz/mqFUXX9bgOTcwEw6xT+OpOt2I2gAbQRbTm4LIU2bM+8knW5fAC8ZZ584h3IRiXcoOuP16M+uBagg==
Verified for
  • Cisco
  • DocuSign
  • Microsoft 365

Email authentication strong

SPF
v=spf1 mx include:spf.zixsmbhosted.com ip4:208.95.207.80/28 ip4:208.64.241.24/29 ip4:208.64.242.48/29 ip4:68.232.131.30 ip4:68.232.140.103 ip4:68.232.143.79 ip4:192.254.121.248 ip4:168.215.212.0/24 ip4:205.220.186.227 ip4:199.30.235.72 include:_spf.sageworks.com include:_spf.psm.knowbe4.com include:spf.cashedge.com include:spf.protection.outlook.com include:emailus.freshservice.com include:spf1.communitywestbank.com -all
strict (-all)
DMARC
v=DMARC1;p=reject;rua=mailto:dmarc@bankonitusa.com;ri=604800;fo=s
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvLqRC3LysoUyHrObbmNRQ4v5A9y11vfiPpRnVZo6tf6zjtznDLE3BLGNafiMhmZySi5/nLnkAk7RCc…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

GeoTrust TLS RSA CA G1
from 2026-02-23 to 2026-08-24
Expires in 95 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://www.communitywestbank.com/

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.g.doubleclick.net *.googleadservices.com *.vimeo.com *.googletagmanager.com *.wistia.com *.bugherd.com *.jquery.com *.googleapis.com *.gstatic.com *.google.com *.google-analytics.com *.facebook.net *.youtube.com *.twitter.com *.onlineaccess1.com *.audioeye.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.google.com *.typekit.net *.fontawesome.com *.audioeye.com; font-src * data:; img-src * data:; media-src 'self' data: blob: *.wistia.com; child-src 'self' blob: *.twitter.com *.youtube.com *.vimeo.com *.bugherd.com *.google.com *.wistia.com *.wistia.net *.facebook.com *.audioeye.com; connect-src 'self' wss://localhost:* accounts.google.com *.g.doubleclick.net *.google-analytics.com *.google.com *.wistia.com *.bugsnag.com *.pusher.com wss://*.pusher.com *.bugherd.com *.googleapis.com *.audioeye.com;

Linked from (4)