fridayharbor.org

.org crawl

First seen 2026-05-31 · Last seen 2026-06-02 · ok HTTP/1.1 200 1112 ms crawled 2026-06-01

US · 208.90.188.150 · AS36489 IP Pathways, LLC

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Friday Harbor, WA | Official Website
Language
en

Technology

jQuery
3.7.1
Stack
ASP.NET

Third-party hosts loaded (1)

  • docaccess.com×1

Social

Contact

Phone

DNS records live

NS
  • ns27.domaincontrol.com
  • ns28.domaincontrol.com
MX
  • 0 fridayharbor-org.mail.protection.outlook.com
Verified for
  • Apple
  • Zoom

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:dmarc-reports@fridayharbor.org; fo=1; aspf=r; adkim=r
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxDTJLlWxji5n9eO1IcPF27vBB6gb4cqQrFUglxNmflyzRzHoqdTXSb/LG2QyI5aDs/ySdoYCLILge5tfEgD…
selectors probed

Certificate (current)

R12
from 2026-04-10 to 2026-07-09
Expires in 36 days

HTTP security headers

Header hygiene 50/100 Checked live page: https://fridayharbor.org/

present
  • content-security-policy
  • x-content-type-options
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
frame-ancestors 'self' https://*.granicus.com https://platform.civicplus.com https://account.civicplus.com https://analytics.civicplus.com; img-src * data: blob:; worker-src * data: blob: 'unsafe-eval' 'unsafe-inline'; script-src * about: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; media-src * blob:; font-src * data:; default-src *

Links to (7)

Linked from (2)