eganco.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress 6.8.3
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- www.googletagmanager.com×5
- fonts.googleapis.com×2
- px.ads.linkedin.com×1
- www.facebook.com×1
Social
Registration
- Registrar
- Wild West Domains, LLC
- Created
- 1997-02-14
- Expires
- 2027-04-26 324 days left
- Updated
- 2023-04-27
- Name servers
-
- ns4.eganco.com
- ns5.eganco.com
DNS records live
- NS
-
- ns5.eganco.com
- ns6.eganco.com
- MX
-
- 500 smtp.google.com
- TXT
-
hpe-greenlake-domain-verification=35784373466d4f44534b616d4531494945764c705971725a517057635237526cautodesk-domain-verification=7xnwmt7DlCAlXQsew53Q
- Verified for
-
- DocuSign
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:authsmtp.com include:app.teamsupport.com include:greenemployee.com ip4:70.35.96.128/26 ip4:129.228.55.32/27 ip4:4.4.131.192/27 ip4:4.1.190.131 ip4:71.39.104.53 ip4:75.146.34.221 ip4:4.1.190.42 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarcreports@eganco.com,mailto:dmarc@xmkhr3cg.uriports.com; ruf=mailto:dmarcreportforensic@eganco.com,mailto:dmarc@xmkhr3cg.uriports.com; pct=100; adkim=r; aspf=rpolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCYnCAZqzmZW3HU1KrR1DqpfnlrwJTr6UYHeOQM0WAKeVttxUa6DhHxjRxG8nxNVRvCS/V+PAS/hwDX+S6cqw… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwxZdsV/0oKBVe0TEy2dqqOHcMsilsdgJASwOaHcj1ww64lzze8KRLdal6EzD5SBHbLPyKifmU98wLIIbpp… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC2TGs3xhOtjE3/HMGmvEUTo/LZlazDU/9NW7izwb9fsTlMjkKxCN1CWlg2AMlnTcoO6KylDO2QX2tzIfvFG7fby6…
selectors probed - google:
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics.google.com https://*.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com https://www.youtube.com https://cdn.outfunnel.com https://reports.hrmdirect.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://www.googleadservices.com https://ddwl4m2hdecbv.cloudfront.net/b/XOE9GHV77POM/XOE9GHV77POM.js.gz https://b-code.liadm.com https://ddwl4m2hdecbv.cloudfront.net/b/GNLKQH79Y46Q/GNLKQH79Y46Q.js.gz https://snap.licdn.com/li.lms-analytics/insight.min.js; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com/ https://fonts.googleapis.com https://reports.hrmdirect.com; connect-src 'self' https://analytics.google.com https://www.google-analytics.com https://stats.g.doubleclick.net https://maps.googleapis.com https://pro.ip-api.com https://a.usbrowserspeed.com https://alocdn.com/c/vn3d8u2u/a/xtarget/p.json https://9xgnrndqve.- strict-transport-security
max-age=31622400; includeSubDomains; preload