foranewworld.org
HTML metadata
Technology
- Server
- BunnyCDN-DE1-1329
- CMS
- Drupal
Third-party hosts loaded (1)
- foranewworld.b-cdn.net×1
Contact
DNS records live
- NS
-
- helium.ns.hetzner.de
- hydrogen.ns.hetzner.com
- oxygen.ns.hetzner.com
- MX
-
- 10 mail2.loopia.se
- 10 mailcluster.loopia.se
- TXT
-
protonmail-verification=48482930c3b18c90eca5a2c6f48a48ef226ac2dbbw=07otAzcRb5c1Cw3jtkEtqiv8VytehztrkWh9LLCQYTZ8
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 include:_spf.protonmail.ch include:spf.loopia.se ip4:212.123.41.224/28 ip4:185.26.229.213/32 ip4:93.188.1.208/29 ip6:2a02:250:0:10::/64 include:_spf.google.com include:spf.mandrillapp.com include:servers.mcsv.net ip4:90.226.101.32/32 ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 34 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- weak frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
ALLOW-FROM https://foranewworld.b-cdn.net/- permissions-policy
geolocation=(self), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src https: data: 'unsafe-inline' 'unsafe-eval'- strict-transport-security
max-age=63072000; includeSubDomains; preload- content-security-policy-report-only
default-src 'self' 'unsafe-inline' https://fanw-1762d.kxcdn.com fanw-1762d.kxcdn.com https://w.soundcloud.com w.soundcloud.com https://www.google-analytics.com google-analytics.com foranewworld.b-cdn.net https://foranewworld.b-cdn.net https://stage.foranewworld.org https://www.foranewworld.org https://foranewworld.org; frame-src 'self' https://player.vimeo.com foranewworld.b-cdn.net https://foranewworld.b-cdn.net https://www.google.com https://www.foranewworld.org https://foranewworld.org https://stage.foranewworld.org; script-src 'self' 'unsafe-inline' *.google-analytics.com *.fanw-1762d.kxcdn.com *.googletagmanager.com *.sndcdn.com fanw-1762d.kxcdn.com https://fanw-1762d.kxcdn.com foranewworld.b-cdn.net https://foranewworld.b-cdn.net https://www.google.com https://www.gstatic.com https://www.google-analytics.com https://stage.foranewworld.org cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://moderate.cleantalk.org https://polyfill
Links to (5)
- paypal.com×1
- iofc.ch×1
- flickr.com×1
- eepurl.com×1
- creativecommons.org×1