dalycity.org
HTML metadata
Technology
- jQuery
- 3.7.1
- Stack
- ASP.NET
Third-party hosts loaded (2)
- answers-script.frase.io×1
- docaccess.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns-1453.awsdns-53.org
- ns-1929.awsdns-49.co.uk
- ns-504.awsdns-63.com
- ns-525.awsdns-01.net
- MX
-
- 0 dalycity-org.mail.protection.outlook.com
- TXT
-
77lb4qda8dl8cg4re7k37r8dl4MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCz6iUhvoi4xWGPQYMzm6KdhzeDGGLtMQoGqqDFuGC6LXJCTUxEUi+BBPGesYvPYIfGMo7sQFAqQlITY/qvvgEx6PsSJwsFgFXFEssr1K6KirWFh6mjv0QNAitcJsbsyqKfPxp0gnIFQ0vclJECLYeLew
- Verified for
-
- Apple
- Microsoft 365
- Zoom
Email authentication strong
- SPF
-
v=spf1 ip4:76.14.93.48/32 include:spf.protection.outlook.com include:_spf.smtp.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_rua@dalycity.org,mailto:o7yur68bf0@rua.powerdmarc.com; ruf=mailto:dmarc_ruf@dalycity.org; fo=1policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCfm17VlLKrYezCMOD2ppGquq77Z93WxiOk/pg+C827g37CJwmihqITX+qR5ItH9HKdz6pUrJYTS/WHgiywE9… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyiO9KlLE6RnpmMM3sbVHykXOUYgODWOBdPZHVcO9kusaN12Arazjtldw2Ukda4XbsAC4hXhqo7qDSZ… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
R12
Expires in 50 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://*.granicus.com https://platform.civicplus.com https://account.civicplus.com https://analytics.civicplus.com; img-src * data: blob:; worker-src * data: blob: 'unsafe-eval' 'unsafe-inline'; script-src * about: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; media-src * blob:; font-src * data:; default-src *