giftofhope.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (4)
- www.googletagmanager.com×2
- gmpg.org×1
- use.typekit.net×1
- www.youtube.com×1
Social
Contact
- Phone
- Address
- 425 Spring Lake Drive, 60143, Itasca, IL, US
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2002-05-15
- Expires
- 2034-05-15 2905 days left
- Updated
- 2025-09-20
- Name servers
-
- nelly.ns.cloudflare.com
- nick.ns.cloudflare.com
DNS records live
- NS
-
- nelly.ns.cloudflare.com
- nick.ns.cloudflare.com
- MX
-
- 10 d215100a.ess.barracudanetworks.com
- 20 d215100b.ess.barracudanetworks.com
- TXT
-
Show 7 TXT records
XfwlcAWf/YfoU35WRXfteuANCT6ACH9nPZqJpmFNOiGl94op7KWOlO2j3byRZY91qJncOdxA27hCwTfp6lIRQA==_hvhwvpazzh3py8494xwb6tsqet96lfdcloudflare_dashboard_sso=f460245bd590027af9cc646ad0a4470fheymarket-domain-verification-nv4p7r=3K2BU4bhPhJRloQ7aXyxhImmminfor-cloudsuite-domain-verification=DLXPLLK9EZMSP2VS47MHSR4KWEXQMKV5FZ8GV5NHSY3LSF62Y5GMFS64SCCPFKZMpax8validateSFMC-5uyZEDqBMrb0vYcCZeugxm8SGTjk3h0fE168eiAX
- Verified for
-
- Apple
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_netblocks.google.com include:_netblocks2.google.com include:_netblocks3.google.com include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com include:_spf.salesforce.com include:spf.constantcontact.com include:relay.mailchannels.net include:inforcloudsuite.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; rua=mailto:434ad13f2fd24d69a0899075e75ff00c@dmarc-reports.cloudflare.net,mailto:rua+giftofhope.org@dmarc.barracudanetworks.com; ruf=mailto:ruf+giftofhope.org@dmarc.barracudanetworks.compolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu9JsXTv27KjrRqsmwbLhm+5cQfsdPTXoer60424DArstWYQLU5Isn+x6OeHJCW/y0TCJXLiOuC7XYA… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA346uOgqN252LFEvzjqh2flcX21hqGVeUaYmh1WN4Eapxp7TpdsZM180NnPPvTCIGFWoGLccRlO+Yi0…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 66 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
autoplay=(), camera=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), publickey-credentials-get=(), usb=(), browsing-topics=()- x-content-type-options
nosniff- content-security-policy
default-src https: data: wss://*.hotjar.com wss://*.crazyegg.com *.crazyegg.com wss://*.zohopublic.com; script-src https: blob: data: 'unsafe-inline' 'unsafe-eval'; style-src https: data: 'unsafe-inline'; img-src data: https: 'unsafe-inline'; font-src data: https: 'unsafe-inline'; frame-ancestors 'self'; object-src 'self' blob; upgrade-insecure-requests; media-src 'self' blob: data: https:;- strict-transport-security
max-age=31536000; preload