cranenxt.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Osano
Third-party hosts loaded (4)
- kit.fontawesome.com×2
- cmp.osano.com×1
- gmpg.org×1
- www.googletagmanager.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2022-02-25
- Expires
- 2027-02-25 281 days left
- Updated
- 2025-05-30
- Name servers
-
- ns33.domaincontrol.com
- ns34.domaincontrol.com
DNS records live
- NS
-
- ns33.domaincontrol.com
- ns34.domaincontrol.com
- MX
-
- 10 mx0a-00780001.pphosted.com
- 10 mx0b-00780001.pphosted.com
- TXT
-
Show 5 TXT records
MS=ms57233888google-gws-recovery-domain-verification=69274929smartsheet-site-validation=NfL7h7H93FFycwn3h-KLlnPtvoZ1v2LZdls8xtx4znjz33dgeec3google-site-verification=ReUxSIwOG10u3exUwsgcv1KRTWDV3Ds8jfUiBGav5lE
Email authentication partial
- SPF
-
v=spf1 ip4:20.122.133.142 ip4:13.77.71.160 ip4:52.176.179.69 ip4:70.33.230.67 ip4:172.172.68.149 ip4:20.12.196.164 ip4:48.211.248.26 include:_spf.psm.knowbe4.com include:spf-00780001.pphosted.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), autoplay=(self), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(self), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(self), midi=(), payment=(), picture-in-picture=(self), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(self), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' *.osano.com *.fontawesome.com *.google-analytics.com *.googletagmanager.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; img-src 'self' data: secure.gravatar.com *.googletagmanager.com; font-src 'self' data: fonts.gstatic.com *.fontawesome.com; connect-src 'self' *.fontawesome.com *.google-analytics.com *.analytics.google.com *.osano.com; media-src 'self'; frame-src 'self' *.doubleclick.net *.taleo.net *.youtube.com; worker-src 'self' blob:- strict-transport-security
max-age=63072000; includeSubDomains; preload