crossway.org
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- d33n9snnr16ctp.cloudfront.net×6
- cdn.fonts.net×1
- www.facebook.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 1996-09-29
- Expires
- 2030-09-28 1593 days left
- Updated
- 2025-02-20
- Name servers
-
- ns2.crossway.org
- ns1.crossway.org
- ns3.crossway.org
DNS records live
- NS
-
- ns1.crossway.org
- ns2.crossway.org
- ns3.crossway.org
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
Show 8 TXT records
anthropic-domain-verification-2yvtv6=6QKoQMJujeEPPjTUYvPKiEIVBfacebook-domain-verification=6dtxskoywtxzapxbr9cdvgh9j7bsons6vsftbt8ml5bhd2c256qk02jxcw703lgoogle-site-verification=Jd2z7Z5JWNB2AkIWZxod-d43ZJbGLoAFcN_uATQuymkMS=ms14995406asv=20e02f5b73106bfb6b5a9205d5441cf7apple-domain-verification=nQejJOYBiKpofYm_4UsNZEuinC4ytaq55Qx_8z1mu6oasv=4572509380f3320e09121253b7641f71
Email authentication partial
- SPF
-
v=spf1 include:_spf.crossway.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-reports@crossway.org,mailto:dmarc@crossway.uriports.com; ruf=mailto:dmarc-reports@crossway.org,mailto:dmarc@crossway.uriports.com; fo=1:d:spolicy: none (monitoring only) - DKIM
-
- k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - k1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 84 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src https:; script-src 'unsafe-inline' 'unsafe-eval' blob: https:; style-src 'unsafe-inline' https:; font-src https: data:; media-src http: https:; img-src http: https: data:- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin
Links to (5)
- esv.org×2
- facebook.com×2
- instagram.com×2
- x.com×2
- youtube.com×2