familyassets.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2004-08-08
- Expires
- 2026-08-08 80 days left
- Updated
- 2024-08-09
- Name servers
-
- ns-1021.awsdns-63.net
- ns-1059.awsdns-04.org
- ns-1560.awsdns-03.co.uk
- ns-67.awsdns-08.com
DNS records live
- NS
-
- ns-1021.awsdns-63.net
- ns-1059.awsdns-04.org
- ns-1560.awsdns-03.co.uk
- ns-67.awsdns-08.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 5 TXT records
activeprospect-domain-verification=posvfLgUKGeMq7xgmjqS8w==apple-domain-verification=qZxhD0iCiY962YzSbrevo-code:613a74014d5b5433cfc84adad20075fbgoogle-site-verification=83TcypcfK5Hmif3CR-zdhivpbkBM39oyAf4UHLENXkUgoogle-site-verification=sSgDtAlXz-aVvSMuTFI5GRsDwrGalo2WmGjUUeB74dc
Email authentication partial
- SPF
-
v=spf1 include:customeriomail.com include:spf.mandrillapp.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; fo=1; rua=mailto:wpadmin@familyassets.compolicy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxlDojb626qwEp4Xry6stvV/2OIz8F6i4KGTTFAtwmrGdoWoFMxsG/smUyPyJBAzOSdQp9ZUWvDf2rI3WlO… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC79E+/ipinvmTspDu3GOrmTChkVzg40B5z4q+jfB+bb31vmz37A/OsFSwsXxEhAqjQQoL3SZJKpPGIoLOxo3RN6/… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - s1:
Certificate (current)
Amazon RSA 2048 M01
Expires in 158 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
script-src 'self' *.familyassets.com 'unsafe-inline' 'unsafe-eval' www.google.com www.gstatic.com www.recaptcha.net *.googletagmanager.com script.crazyegg.com tag.simpli.fi i.simpli.fi mm-uxrv.com *.doubleclick.net connect.facebook.net *.hotjar.com *.hs-scripts.com js.hsforms.net js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net *.liadm.com *.usbrowserspeed.com *.aisiteanalytics.com *.botsrv2.com botsrv2.com *.leadgenapp.io form.cliqforms.com *.trustedform.com api.useleadbot.com *.getleadforms.com; worker-src 'self' blob: data:; img-src 'self' *.familyassets.com blob: data: api.leadgenapp.io *.leadgenapp.io p1.socds.net *.botsrv2.com botsrv2.com www.googletagmanager.com *.google.com *.google.com.co *.google-analytics.com *.googleadservices.com www.gstatic.com script.crazyegg.com *.simpli.fi *.doubleclick.net *.facebook.com *.hotjar.com track.hubspot.com forms.hubspot.com *.liadm.com api.trustedform.com api-static-files.s3.amazonaws.com; font-src 'self' *.familyassets.com fon