givingpledge.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- fonts.googleapis.com×4
- fonts.gstatic.com×3
- www.googletagmanager.com×2
- www.youtube.com×2
- gmpg.org×1
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 2010-03-10
- Expires
- 2027-03-10 295 days left
- Updated
- 2025-05-14
- Name servers
-
- romina.ns.cloudflare.com
- rustam.ns.cloudflare.com
DNS records live
- NS
-
- romina.ns.cloudflare.com
- rustam.ns.cloudflare.com
- MX
-
- 1 givingpledge-org.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
MS=ms39679726google-site-verification=qnB4chfIoAju-hFJzdga7QnA6TfHCWQLSxmux6T9wKMpardot844003=ce41c102472ba80b20c554efa33d38eb4b802d76a55ad5f2b056a5b4aada7a43x28839jx06sq9d60q7v3fl7zdhvpvkc2
Email authentication strong
- SPF
-
v=spf1 exists:%{i}._i.%{d}._d.espf.agari.com include:%{d}.7c.spf-protect.agari.com include:helpscoutemail.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:gates-foundation@rua.agari.com; ruf=mailto:gates-foundation@ruf.agari.compolicy: reject (enforced) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv9zGwBQ4iFWhQv751mofdR0JSoRgfinRAqdjLlEekFRratpw9jJYyIw0a1lhUdo80hNnCS5OIS5Ag6zJJK… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1oC4pojk6U5AYwHKnOyXueAsqa/3Jt4+P6elMNAMKtT+9HUtqneG88kBA+Kz3LuOEDXIpHQZ6mD76kqPNX…
selectors probed - s1:
Certificate (current)
WE1
Expires in 29 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=*, geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-script=(), sync-xhr=(), usb=(), vertical-scroll=(), web-share=*, xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' http: https://*.f1gf.dev https://*.f1gf.live https://*.givingpledge.org https://*.gatesfoundation.org https://*.youtube.com; script-src 'unsafe-inline' 'unsafe-eval' http: https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.youtube.com https://analytics.google.com https://*.google-analytics.com https://*.ytimg.com https://*.moatads.com https://*.doubleclick.net https://cdnjs.cloudflare.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://privacyportal.onetrust.com https://geolocation.onetrust.com https://googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.googleadservices.com https://google.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net; style-src 'unsafe-inline' http: https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.youtube.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https- strict-transport-security
max-age=31536000; includeSubDomains; preload