hcbe.net
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- content.myconnectsuite.com×31
- code.jquery.com×1
- content.schoolinsites.com×1
- maxcdn.bootstrapcdn.com×1
- translate.google.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- eNom, LLC
- Created
- 2000-06-13
- Expires
- 2026-06-13 25 days left
- Updated
- 2025-06-08
- Name servers
-
- dawn.ns.cloudflare.com
- houston.ns.cloudflare.com
DNS records live
- NS
-
- dawn.ns.cloudflare.com
- houston.ns.cloudflare.com
- MX
-
- 0 us-smtp-inbound-1.mimecast.com
- 0 us-smtp-inbound-2.mimecast.com
Email authentication partial
- SPF
-
v=spf1 ip4:168.10.192.3 include:us._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.salesforce.com include:customerspf.schoolmessenger.com include:mg.infinitecampus.org -allstrict (-all) - DMARC
-
v=DMARC1;p=none;sp=none;pct=100;rua=mailto:administrator@hcbe.net;ruf=mailto:administrator@hcbe.net;ri=86400;aspf=s;adkim=s;fo=1policy: none (monitoring only) · sp=none - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDe73OpBaXvD5uy+EGPIQEUZl7nRPYW5oSZldDGTvtiNIwmigNhRD2G+QSpMBuXWTCKGUEej79/cZUc1UPrpT… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzbhS0+CMbcN7efoun9ypN/IxL/9ZdxdoSnZtlB3kQJwJO6fQf+jNER3Gnf1SvbvKgUKbM317wkXm1XJmJ+wIK7ErcEbB… - s1:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtlKfpHPXy+3xADqF1Jg4gvyRUc9riR4Hua8KdmCAFoZtlObC/oMYB6C5POHW0BlNR1kkyK9acxcMogYdDfnfDo9… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCz2d1qhJUycP3UzBsRoYQVCqcYwEjxu6LgtReXDT57CaPZyo5fAPSogsl6C2xxVk5dRUVPTKrWMOHF9GBgRIBCgi…
selectors probed - selector2:
Certificate (current)
R13
Expires in 16 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' *.myconnectsuite.com *.schoolinsites.com *.pcmac.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' *; font-src 'self' *; base-uri 'self'; form-action 'self' 'unsafe-inline' *; img-src 'self' *; connect-src 'self' *; frame-src *; media-src 'self' blob: *; worker-src 'self' blob: *- strict-transport-security
max-age=63072000; includeSubDomains