expocenter.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- 2025 North Expo RoadPortland, Oregon 97217
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1998-07-07
- Expires
- 2027-07-06 412 days left
- Updated
- 2024-11-14
- Name servers
-
- curt.ns.cloudflare.com
- lina.ns.cloudflare.com
DNS records live
- NS
-
- curt.ns.cloudflare.com
- lina.ns.cloudflare.com
- MX
-
- 10 mx1.hc5694-77.iphmx.com
- 10 mx2.hc5694-77.iphmx.com
- TXT
-
google-site-verification=D2csL2cT8ZKr04O-FH5K45rTP8qRSUIybBzDHix_Hxcknowbe4-site-verification=372430689f1f27a9279c2f53453c8b47rovag_verification_token=3C244D56E5AA47448D47182B47982BFF
Email authentication partial
- SPF
-
v=spf1 exists:%{i}.spf.hc5694-77.iphmx.com ip4:198.236.86.41 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:1rua@oregonmetro.gov; ruf=mailto:1ruf@oregonmetro.gov; fo=1policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
WE1
Expires in 72 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' https://www.facebook.com https://analytics.google.com https://drupal-oauth.mailchimp.com https://www.google-analytics.com https://www.googletagmanager.com; font-src 'self' data: fonts.gstatic.com use.typekit.net; frame-src 'self' data: https://www.facebook.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://www.instagram.com https://www.canva.com https://*.doubleclick.net https://challenges.cloudflare.com; img-src 'self' data: https://www.facebook.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.amazonaws.com https://www.google-analytics.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://connect.fac- strict-transport-security
max-age=63072000; includeSubDomains; preload