discoverfrederickmd.com
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (3)
- docaccess.com×1
- www.googletagmanager.com×1
- www.youtube.com×1
Social
Contact
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1999-05-03
- Expires
- 2027-05-03 349 days left
- Updated
- 2024-01-25
- Name servers
-
- ns20.digicertdns.com
- ns21.digicertdns.com
- ns22.digicertdns.com
- ns23.digicertdns.net
- ns24.digicertdns.net
- ns25.digicertdns.net
DNS records live
- NS
-
- ns20.digicertdns.com
- ns21.digicertdns.com
- ns22.digicertdns.com
- ns23.digicertdns.net
- ns24.digicertdns.net
- ns25.digicertdns.net
- MX
-
- 10 mx1.emailsrvr.com
- 20 mx2.emailsrvr.com
- TXT
-
google-site-verification=jMbkAnvjDD2iLbE1YpWFfbI8rbEB154F65k58XDHbCI
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoaReChcoFTiYu+fAJgEOZr1qXP/Tvxq+zk5UwGQLOuuxQ/ZQfpbyv7505VZ2RwQV8zPFQI8BOOH1K/ORv/… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9N6zV7n5K/DqWVFLNwc9Z+Rxw0g0QosTb8U5X+BS0Y4TZZ3dsRDp3PL0tmQWFUB3K8y4dIgUD1ivT7yRRM…
selectors probed - s1:
Certificate (current)
R13
Expires in 36 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://*.granicus.com https://platform.civicplus.com https://account.civicplus.com https://analytics.civicplus.com; img-src * data: blob:; worker-src * data: blob: 'unsafe-eval' 'unsafe-inline'; script-src * about: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; media-src * blob:; font-src * data:; default-src *