freedomfromtorture.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Drupal
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
Third-party hosts loaded (3)
- static.cloudflareinsights.com×1
- www.fundraisingregulator.org.uk×1
- www.googletagmanager.com×1
Social
Contact
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 2010-12-07
- Expires
- 2028-12-07 931 days left
- Updated
- 2025-10-11
- Name servers
-
- augustus.ns.cloudflare.com
- frida.ns.cloudflare.com
DNS records live
- NS
-
- augustus.ns.cloudflare.com
- frida.ns.cloudflare.com
- MX
-
- 0 freedomfromtorture-org.mail.protection.outlook.com
- TXT
-
Show 8 TXT records
jtja0r4o5vvf3m1uhs4eeefbcosophos-domain-verification=d02de12d03814ba020312be1f944025d68ec8c136d727f37f80dc8b67fb5d626uqm4mtunjuutirdr7c06knfb554ie52da25527ra201v8qbqp4cf6tBjuhrzpAVkkA/Qf4yK04oDiK0+AEnTFoyrG7EG1e3L1vHv7oUGfoBG1mFLf7jFOfspVTlF1IvcNRnvP/DnyA==815aqttrcbv3q9vr1e0ch3qq4qaccess-domain-verification=137c8e0727332efa4c02da9e9dfaf508ad674f4c722f7cc3667697822b1726f2ca3-cf601af0a280492f92bac23325973c4b
- Verified for
-
- Apple
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a mx ip4:52.50.68.178 ip4:77.89.152.199 ip4:77.89.152.194 ip4:185.199.222.4 ip6:2a03:2800:500::228 include:spf.protection.outlook.com include:_spf.elasticemail.com include:mailgun.org include:_spf.e-activist.com include:spf2.accessacloud.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:1c999a3020c94dec91e61e36a7eff409@dmarc-reports.cloudflare.netpolicy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArXySx/UIK+vPnqwJEydgaLZIEDk1mZux0FM6ZC7Qx0eLOplj43TDrC2yHHN1Hoig3icHQpr7aiWeZ6…
selectors probed - default:
Certificate (current)
WE1
Expires in 79 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob:; connect-src 'self' https://*.tawk.to wss://*.tawk.to *.visualwebsiteoptimizer.com app.vwo.com d.adroll.com s.adroll.com bat.bing.com bat.bing.net *.clarity.ms https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://www.facebook.com www.googletagmanager.com *.google-analytics.com *.googlesyndication.com *.google.com *.google.co.uk https://gtm.freedomfromtorture.org googleads.g.doubleclick.net *.googleads.g.doubleclick.net stats.g.doubleclick.net l.sharethis.com https://apikeys.civiccomputing.com https://clapi.civiccomputing.com cloudflareinsights.com https://*.omappapi.com https://*.optimonk.com; font-src 'self' https://*.tawk.to https://fonts.gstatic.com https://*.hotjar.com https://*.fundraisingregulator.org.uk https://*.optimonk.com data:; frame-src *; img-src 'self' https://*.tawk.to https://cdn.jsdelivr.net https://tawk.link https://s3.amazonaws.com *.visualwebsiteoptimizer.com app.vwo.com chart.googleapis.com d.adroll.com s.adroll.com *.d.adro- strict-transport-security
max-age=15552000; includeSubDomains; preload