cornerstoneondemand.com
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- play.vidyard.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Network Solutions, LLC
- Created
- 2004-03-22
- Expires
- 2030-03-22 1401 days left
- Updated
- 2020-05-11
- Name servers
-
- ns1.p27.dynect.net
- ns2.p27.dynect.net
- ns3.p27.dynect.net
- ns4.p27.dynect.net
- udns1.ultradns.net
- udns2.ultradns.net
DNS records live
- NS
-
- ns1.p202.dns.oraclecloud.net
- ns2.p202.dns.oraclecloud.net
- ns3.p202.dns.oraclecloud.net
- ns4.p202.dns.oraclecloud.net
- udns1.ultradns.net
- udns2.ultradns.net
- MX
-
- 10 mxa-002d2501.gslb.pphosted.com
- 10 mxb-002d2501.gslb.pphosted.com
- TXT
-
Show 8 TXT records
qgavihckpemufv71tmj3d5camrqnvfdr6qfkfvt06p7cdcl8fv3and7sojajb4mvf8p1odjptvbi1rparallels-domain-verification=df5fdd90e80148eabd57d2db656e7b7f93140e1e69b7488d8eb39eec0ec0da45O+j2viY6uhaWpdSyAfCC1i0tGe74c5FhxyXRuB2W9WeIMr3Q28svEt8iNXEA8mJBbIe5lO4QmkQIxe87Y6yErg==hj-ownership=891083-28052024c212d03eb6d84fd2b4fa5000c1b0425dstatus-page-domain-verification=djpbnmpnhkmc
- Verified for
-
- Atlassian
- Cisco Webex
- Meta
- Microsoft 365
- OneTrust
- Slack
Email authentication strong
- SPF
-
v=spf1 include:spf1.cornerstoneondemand.com include:spf2.cornerstoneondemand.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; fo=1; aspf=r; rua=mailto:32e8d942@mxtoolbox.dmarc-report.com; ruf=mailto:32e8d942@forensics.dmarc-report.compolicy: reject (enforced) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA12CX7FW+IKJLcgrUV8ql6nasl5HlKoGYelN2hmFo2FfI+2ZgyTyKLgtcXZTg0AcmIWIzeSSSeuFIOTo7+I… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDip7kyi3eIelE88ih53MTZacSgyVrXheOU/OycLcOIMHeLd6qtdkNRxdDDT1uSI5PwMsbF9Yurgw0wgNusfmrV06…
selectors probed - s1:
Certificate (current)
R13
Expires in 57 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
camera=(), microphone=(), geolocation=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://*.cornerstoneondemand.com https://csod-studio.vercel.app https://*.csod-preview.com https://*.sanity.io https://*.sanity.studio;upgrade-insecure-requests;default-src 'self' https://*.cornerstoneondemand.com;connect-src *;font-src * data:;form-action *;frame-src *;img-src * data:;manifest-src * 'unsafe-inline';media-src *;object-src *;script-src * 'unsafe-eval' 'unsafe-inline' blob:;style-src * 'unsafe-inline';worker-src * blob:- strict-transport-security
max-age=63072000; includeSubDomains; preload