hbtf.com
HTML metadata
Technology
Third-party hosts loaded (1)
- cdn.jsdelivr.net×3
Social
Contact
Registration
- Registrar
- Talal Abu Ghazaleh Intellectual Property "AGIP" S.A.L. (offshore)
- Created
- 2001-01-10
- Expires
- 2027-01-10 234 days left
- Updated
- 2026-01-11
- Name servers
-
- ns1.hbtf.com.jo
- ns2.hbtf.com.jo
DNS records live
- NS
-
- ns1.hbtf.com.jo
- ns2.hbtf.com.jo
- ns3.hbtf.com.jo
- TXT
-
Show 6 TXT records
9g206r3ptst0rrf3b9l981xt2ztzq4g8dtm-domain-verification=PqodGIuwfF-MGQJKt2HKUyuV79Uu47q506TssyS5JVo_urgmdxzz0e54yw9cn4j8wp8nc56k0gwtrend-micro-v1-domain-verification.d8ff05bc18e96f88ee4080d4f8e7a441=bb5868a3-600a-47d7-b3f2-26d83788a31b_m67dn7zf5593vzpf0cfj2f5bbfs6h58rovag_verification_token=38E96AA6F7B44AA7B5EA4A903F68F93E
Email authentication no MX
- SPF
-
v=spf1 ip4:141.0.0.109 include:spf-00822301.pphosted.com include:spf.messagelabs.com include:spf.protection.outlook.com include:spf-uae.emailsignatures365.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com,mailto:57fd6081@inbox.ondmarc.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com,mailto:57fd6081@inbox.ondmarc.com; adkim=s; aspf=s; rf=afrf; pct=100policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 202 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.openweathermap.org *.googletagmanager.com *.google-analytics.com *.googleapis.com *.google.com *.gstatic.com *.readspeaker.com *.jsdelivr.net *.jquery.com *.exchange.jo *.cloudflare.com ; style-src 'self' 'unsafe-inline' *.googleapis.com *.readspeaker.com *.jsdelivr.net chatbot.hbtf.com.jo *.bootstrapcdn.com *.exchange.jo *.fontawesome.com *.stackpath.bootstrapcdn.com ; img-src 'self' data: *.google-analytics.com *.readspeaker.com *.gstatic.com *.google.com *.googleapis.com i.ytimg.com *.google.jo *.botter.live *.hbtf.com.jo *.amazonaws.com *.icons8.com *.digitaloceanspaces.com *.exchange.jo; connect-src 'self' *.readspeaker.com *.google-analytics.com stats.g.doubleclick.net *.googleapis.com *.hbtf.com.jo wss://chatbot.hbtf.com.jo *.miglisoft.com *.openweathermap.org ; font-src 'self' *.gstatic.com data: cdn.jsdelivr.net *.bootstrapcdn.com; object-src 'self'; media-src 'self' notificationsounds.com *.readspeaker.c- strict-transport-security
max-age=16070400; includeSubDomains
Links to (10)
- e-hbtf.com×1
- facebook.com×1
- google.com×1
- instagram.com×1
- linkedin.com×1
- microsoft.com×1
- mozilla.org×1
- tiktok.com×1
- twitter.com×1
- youtube.com×1