contourairlines.com

.com crawl

First seen 2026-04-13 · Last seen 2026-05-08 · ok HTTP/1.1 200 327 ms crawled 2026-05-07

BE · 34.14.25.197 · AS396982 Google LLC

Reputation 54/100 listed in spam blocklist dmarc monitor-only

Classifying

HTML metadata

Title
Home
Language
en-gb
Generator
VTE v4.9.1, .com
Translations
  • en
  • es
Feeds

Technology

Server
Apache
CMS
Joomla
Analytics
  • Google Tag Manager
Fonts
  • Adobe Fonts

Third-party hosts loaded (4)

  • cdnjs.cloudflare.com×2
  • www.googletagmanager.com×2
  • cdn.jsdelivr.net×1
  • use.typekit.net×1

Social

Registration

Registrar
GoDaddy.com, LLC
Created
2016-01-19
Expires
2028-01-19 608 days left
Updated
2026-01-20
Name servers
  • ns09.domaincontrol.com
  • ns10.domaincontrol.com

DNS records live

NS
  • ns09.domaincontrol.com
  • ns10.domaincontrol.com
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • 46h0eta4iac3ute1i6cg5fsrj
  • n6f3q32310o9022b77d72nqq5e
Verified for
  • Google

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:spf.mandrillapp.com include:_spf.smtp.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:dmarc@contourairlines.com
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCwHVYjYh15js8kIDuPpyKr7YQcTygzzlLPb44ZA12/Q5Pz/IXpIs7w45boU4BQ8eCOP49Lndw6JxA9LnQGDr…
selectors probed

Certificate (current)

R13
from 2026-03-18 to 2026-06-16
Expires in 26 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://contourairlines.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src * 'self' 'unsafe-inline' 'unsafe-eval' ; script-src * 'self' 'unsafe-inline' 'unsafe-eval' ; style-src * 'self' 'unsafe-inline' ; img-src * 'self' data: ; frame-src * ; font-src * 'self' data: ;
strict-transport-security
max-age=63072000; includeSubDomains

Links to (6)

Linked from (3)