freemanhealth.com
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×5
- assets.sitescdn.net×2
- tag.brandcdn.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1999-03-30
- Expires
- 2028-04-01 682 days left
- Updated
- 2025-04-04
- Name servers
-
- ns53.domaincontrol.com
- ns54.domaincontrol.com
DNS records live
- NS
-
- ns53.domaincontrol.com
- ns54.domaincontrol.com
- MX
-
- 10 us-smtp-inbound-1.mimecast.com
- 10 us-smtp-inbound-2.mimecast.com
- TXT
-
Show 15 TXT records
jamf-site-verification=CNyQGNkacCZ-xlX5E-vxyAcisco-ci-domain-verification=3e8d6b872706af377112c404dd3ada09159f86d4481bb207d6e562e6fc007e86citrix.mobile.ads.otp=higfsxbrylb827c7s3bujxmhintersight=feaf980f8840ef7e6ac2201e94e6ae16c68b21aeb08817a1cc4dfdafe4ea47c7google-site-verification=t5mGvm3dqmRMyZDkQ5dCpLRtlb0qPJHc0iis2_NKAWAMS=86C089D350F0760DF242D1E65296496514188B8627705f85efd4e133a572fed427432474f297d75947k0kVJkd372kRDKJ7sBmefA8TmBnMRva+/sfW2C8DuNp6bL4O08MBiu9S+ir7Mr9Z80O0yUfjscizTB8ZGR2w==duo_sso_verification=iSFCe6UyxQLvCr1vmU4cnkvMvrLqX5q4tPmMr6ncAgv31XvOypYsk77DMKuIQMCnzXjJWyS0ldIQY8kFOhWIZjjcwZl8VYzEPT7cN/3c+HP+Dp26Oata1MKi4bbRr3/Uy4jpVzMst7gYUUanTYdYFQ==apple-domain-verification=AfxPvJe8cIcpvBDfgoogle-site-verification=PxQ715VM_i3COqQ5JrgdUejCBSZijY7kO7Ssu7nDMcspaloaltonetworks-site-verification=abbb10b6cc00e64959b46a968f41cb8c4f645a02d2f8f71dd98cdc3782c585a0google-site-verification=AIg9Md3TslqLgIyYxYzvctU_JCQRqvQUNjxPRLL6PAggoogle-site-verification=SNq4PT8yh-41vhauSRFySB7iDB9eb48hM072zYTIro0
Email authentication strong
- SPF
-
v=spf1 ip4:63.25.143.30 ip4:64.74.110.101 ip4:12.156.158.249 include:spf.protection.outlook.com include:us._netblocks.mimecast.com include:spf.constantcontact.com include:outboundmail.blackbaud.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; rua=mailto:itsecurity@freemanhealth.com; ruf=mailto:itsecurity@freemanhealth.com; sp=none; ri=86400policy: quarantine · sp=none - DKIM
-
Show 4 DKIM selectors
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5IoB/9VCj8CkdcB4j3Sh wIflJKhthgOzEVZrC516oNjUqBSxQbjWJGnMfVIYq9LHGi3ToM1ttBj41… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQClbdp21My1W3QuiAqPAHKNvH3riWDpxNQ8fxHZmEUPptPE4WQtCXHyp07Q4o6k4FQBn8YcCQb0tH4+mVIHi4… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo4rapiD4LHEfVSApBwrZu7CdaWn1XtUADzJJMxzEPgXvtuC90Eu3zKWwX8ddUs9f33zK0YU/1rd0uiJ+Vj… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDepbQ/r3ITINNLaHYWoHaIe7V1fiLmIqcLnjoH0KBtvdtVbrlW/fsvCeDVT+Lh5Pf0Prblfa8aoESUki2ey4dmNB…
selectors probed - default:
Certificate (current) wrong cert
Entrust OV TLS Issuing RSA CA 2
Expires in 191 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- checked over plain HTTP
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.acquia-sites.com http://freemanhealth1dev.prod.acquia-sites.com/ https://www.freemanhealth.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.youtube.com unpkg.com *.adsrvr.org *.pagescdn.com cdn.jsdelivr.net cdnjs.cloudflare.com *.google-analytics.com *.googletagmanager.com adservices.brandcdn.com assets.sitescdn.net *.acquia-sites.com tag.brandcdn.com sky.blackbaudcdn.net; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.acquia-sites.com assets.sitescdn.net cdnjs.cloudflare.com; img-src 'self' data: https: *.adsrvr.org *.google-analytics.com; media-src 'self' 'unsafe-inline' 'unsafe-eval' *.youtube.com *.youtube-nocookie.com youtu.be www.youtube.com *.adsrvr.org *.pagescdn.com *.google-analytics.com *.googletagmanager.com adservices.brandcdn.com assets.sitescdn.net *.acquia-sites.com tag.brandcdn.com; frame-src 'self' *.youtube.com *.youtube-nocookie.com *.youtu.be www.youtube.com *.cloudfront.net *.brandcdn.com insight.adsrvr.org *.acquia-sites.com- strict-transport-security
max-age=31536000; includeSubDomains; preload