geretyawards.com
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (7)
- ae-prod-assets.awardsengine.com×8
- ae-prod-assets.s3.eu-west-1.amazonaws.com×6
- ae-uat-assets.s3-eu-west-1.amazonaws.com×4
- cdn.jsdelivr.net×2
- ae-int-assets.awardsengine.com×1
- cdn-images.mailchimp.com×1
- s3.amazonaws.com×1
Social
Contact
- Phone
- Address
- st mockPlaceholders = [ { countryCode: 'US', placeholder: '+1 000 000 0000
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2018-06-26
- Expires
- 2027-06-26 402 days left
- Updated
- 2024-06-18
- Name servers
-
- ns07.domaincontrol.com
- ns08.domaincontrol.com
DNS records live
- NS
-
- ns07.domaincontrol.com
- ns08.domaincontrol.com
- MX
-
- 0 geretyawards-com.mail.protection.outlook.com
- TXT
-
google-site-verification=UTsZFU7d8KlYm3s9yXN82XcOVUM85k9djnPXplrKX-QNETORGFT4421332.onmicrosoft.comgoogle-site-verification=4aE3lwGgCQkC3pOKKG94nX2OH3A68Lv4TkzF61ftbNQ
Email authentication partial
- SPF
-
v=spf1 include:secureserver.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
Amazon RSA 2048 M01
Expires in 162 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
allow-from *- x-content-type-options
nosniff- content-security-policy
default-src * data: mediastream: blob: filesystem: about: ws: wss: 'unsafe-eval' 'wasm-unsafe-eval' 'unsafe-inline'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src-elem * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline';font-src * data: blob: 'unsafe-inline';frame-ancestors * data: blob:;- strict-transport-security
max-age=31536000; includeSubdomains;