coviacorp.com
HTML metadata
Technology
- Analytics
-
- Google Analytics
- Google Tag Manager
- Cookie consent
-
- Cookiebot
- Fonts
-
- Google Fonts
Third-party hosts loaded (9)
- www.googletagmanager.com×4
- cdnjs.cloudflare.com×2
- www.gstatic.com×2
- consent.cookiebot.com×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- tag.simpli.fi×1
- www.google-analytics.com×1
- www.webtraxs.com×1
Social
Contact
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2018-03-28
- Expires
- 2028-03-28 679 days left
- Updated
- 2023-03-29
- Name servers
-
- ns01.domaincontrol.com
- ns02.domaincontrol.com
DNS records live
- NS
-
- ns01.domaincontrol.com
- ns02.domaincontrol.com
- MX
-
- 10 us-smtp-inbound-1.mimecast.com
- 10 us-smtp-inbound-2.mimecast.com
- TXT
-
Show 7 TXT records
MS=ms98166625Foxit-domain-verification=fe106b0cce3a1b78da2a8066b4a846cbapple-domain-verification=u4AQsHp7mrmXeXDygoogle-site-verification=4tzaHUHAgIUFoVfiVjitlbpiVrk3EuFa2UfZjCZ8FEQsmartsheet-site-validation=udm1EHf1F1oTv5G5BvbntlUnDt1zi1Do1password-site-verification=OGU7RHQI7ZHXNJK6O63M6THJSQ0ed1fe018ace6d8baa80c8412b94d849f1c8505dfa
Email authentication strong
- SPF
-
v=spf1 ip4:4.53.198.232/32 ip4:4.53.198.226/32 ip4:64.125.171.194/32 a:mail.accwebhost.com include:_spf.ultipro.com a:mta1.pd.ipreo.com include:us._netblocks.mimecast.com include:_spf.salesforce.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=quarantine;pct=100;ri=86400;aspf=s;adkim=r;fo=1;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAslYWlCKC8feEGxxu/bGs5fq4fa5aqkXjjwHW4IbA1l/MCtsgOVdyfOtwrMeteQGp16fnRonCemEtyY…
selectors probed - selector1:
Certificate (current)
R13
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=(), camera=(), microphone=(), geolocation=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.coviacorp.com; style-src 'self' 'unsafe-inline' *.gstatic.com *.3blmedia.com *.youtube.com *.twitter.com *.twimg.com *.bootstrapcdn.com *.googleapis.com *.typekit.net *.thunderstone.cloud *.fontawesome.com *.cloudflare.com *.stackadapt.com; font-src 'self' *.3blmedia.com *.youtube.com *.twimg.com *.typekit.net *.cloudflare.com *.gstatic.com *.fontawesome.com *.addthis.com *.twitter.com; worker-src 'self' blob: *.google.com *.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.webtraxs.com *.simpli.fi *.3blmedia.com *.youtube.com *.twimg.com *.twitter.com *.cloudflare.com *.bootstrapcdn.com *.cookiebot.com *.googletagmanager.com *.google-analytics.com *.thunderstone.cloud *.aspnetcdn.com *.google.com *.gstatic.com *.licdn.com *.crazyegg.com *.stackadapt.com *.addthis.com *.addthisedge.com *.moatads.com; connect-src 'self' *.google.com *.webtraxs.com *.linkedin.oribi.io *.3blmedia.com *.youtube.com *.twimg.com *.twitter.com *.google-analytics.com *.cookieb- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin