grandchallenges.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Drupal
- Fonts
-
- Adobe Fonts
- Google Fonts
Third-party hosts loaded (2)
- fonts.gstatic.com×1
- use.typekit.net×1
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 2008-01-31
- Expires
- 2030-01-31 1351 days left
- Updated
- 2025-05-14
- Name servers
-
- romina.ns.cloudflare.com
- rustam.ns.cloudflare.com
DNS records live
- NS
-
- romina.ns.cloudflare.com
- rustam.ns.cloudflare.com
- MX
-
- 100 grandchallenges-org.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 exists:%{i}._i.%{d}._d.espf.agari.com include:%{d}.7c.spf-protect.agari.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:gates-foundation@rua.agari.com; ruf=mailto:gates-foundation@ruf.agari.compolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJo8Vk/BfO4Gv/q3iVpLC7Bb/OAf9o+IYYnqBMeLny1KnNhkHGq6H3heeP7hHU0DY6+tSXvx8t8ucCo0y0b/… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0YFWePxVDNkyUdNgVakpBeGbk2P6ZGI1zn1DV1mJr5LEw2iN7/8fyKDs3HrZMhD8lzyuCSQu0E0A25…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 36 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' *.gates-pre-prod.byf1.dev *.gates-production.byf1.dev *.grandchallenges.org *.youtube.com youtu.be *.youtube-nocookie.com https://www.google-analytics.com/ https://*.googletagmanager.com/ https://fonts.googleapis.com/ https://go.communications.gatesfoundation.org/ https://*.typekit.net/ https://fonts.gstatic.com https://*.cookielaw.org https://bmgf.cloudflareaccess.com https://cdn.plyr.io https://*.ytimg.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' *.gates-pre-prod.byf1.dev *.gates-production.byf1.dev *.grandchallenges.org *.youtube.com youtu.be https://www.google-analytics.com/ https://*.googletagmanager.com/ https://fonts.googleapis.com/ https://go.communications.gatesfoundation.org/ https://*.typekit.net/ https://fonts.gstatic.com https://*.cookielaw.org https://cdn.plyr.io; font-src 'self' https://*.typekit.net/ https://fonts.gstatic.com https://fonts.googleapis.com/ data:;- strict-transport-security
max-age=2592000; includeSubDomains; preload