dferlist.org

.org crawl

First seen 2026-04-22 · Last seen 2026-05-16 · ok HTTP/1.1 200 7522 ms crawled 2026-05-16

US · 40.84.54.203 · AS8075 Microsoft Corporation

Reputation 87/100 weak security headers no dmarc policy

Classifying

HTML metadata

Title
- the DFER List

Technology

CDN
Azure Front Door

Third-party hosts loaded (2)

  • ajax.googleapis.com×1
  • www.google.com×1

Contact

Email
Phone
Address
rd of Elementary and Secondary Education, P.O. Box 4624

Registration

Registrar
GoDaddy.com, LLC
Created
2014-04-14
Expires
2027-04-14 330 days left
Updated
2026-04-15
Name servers
  • ns-1377.awsdns-44.org
  • ns-1922.awsdns-48.co.uk
  • ns-60.awsdns-07.com
  • ns-661.awsdns-18.net

DNS records live

NS
  • ns-1377.awsdns-44.org
  • ns-1922.awsdns-48.co.uk
  • ns-60.awsdns-07.com
  • ns-661.awsdns-18.net
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • bundler-prod-redirect-as.azurewebsites.net

Email authentication weak

SPF
not published
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

GeoTrust TLS RSA CA G1
from 2026-02-17 to 2026-08-18
Expires in 91 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://www.dferlist.org/page/public_spring_2026

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://accessibilityserver.org https://cdn.userway.org/ https://www.google.com/recaptcha/api.js https://www.gstatic.com https://ajax.googleapis.com https://az416426.vo.msecnd.net https://polyfill.io; style-src 'self' 'unsafe-inline' https://*.typekit.net https://*.googleapis.com https://*.bootstrapcdn.com;

Links to (2)

Linked from (1)