hgcapital.com
HTML metadata
Technology
- CDN
- Netlify
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- images.ctfassets.net×16
- www.googletagmanager.com×1
Social
Contact
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 2002-04-02
- Expires
- 2027-04-02 318 days left
- Updated
- 2026-03-29
- Name servers
-
- udns1.cscdns.net
- udns2.cscdns.uk
DNS records live
- NS
-
- udns1.cscdns.net
- udns2.cscdns.uk
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 15 TXT records
nitro-verification-code=LTg2NDc5NzE5MDM0NDQwMjUwOTc=openai-domain-verification=dv-mw8einnx3UmijaSoo21d4yzesmartsheet-site-validation=e37vXdfc1PHGye5whEsC2C7bisoAaYkAteamviewer-sso-verification=54cd3695015248829c911699c87a96a9work-os-domain-verification-rxcrh3=niTk4QHx10kIzEq1BVoR99nNHperplexity-ai-domain-verification-aj7c6p=iEdi9tATZ9eJ6a12dYsCMLOQXgoogle-site-verification=-BrKRbA_nUHgejwRlQ_q40iX0RYk5LDrphhL41Lsv44google-site-verification=U0X9aFHW8VFNQL6E4js5HBpcy-HuRKpUo3AFgj_NnAEnotion-domain-verification=SCxPYEUOCW3BtcDo2SqXn00ATeT3w9xNwxNl0q7g20N42h8b57sgijbc32vl4am67ru99ZOOM_verify_nrRs69JpV7dBqD8x3IoEijlinear-domain-verification=hwuadm55uxuyapple-domain-verification=eAYMYYR090g7KvNJdocusign=96a0c690-8b6e-472a-bc20-e1f0fccf5407jamf-site-verification=ptMyQg6GaRewzfzdSDmWYQ
Email authentication strong
- SPF
-
v=spf1 include:eu._netblocks.mimecast.com include:sendgrid.net include:spf.protection.outlook.com mx include:spfhost.messageprovider.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:446a5c8cac5d013@rep.dmarcanalyzer.com; ruf=mailto:446a5c8cac5d013@for.dmarcanalyzer.com; fo=1;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCFgqIj9qy2nqSoyGkKkFSij/OfoV7PxVU/3u6mYvpCIhbp8hU1XOWSSwV5pdw/RSybySgtE2EdHwkGq6pegU… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAy5b5HhyiXqS+MjvY6HS1Fy0fZ85twZ5uCpoIAHkUv/CFiZ0X9ADp31AQtdM3zb1t9CTy7/UGyuf/QB8TRu… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+1NZVx2Q62vyCSnt/2giko9K8jTJIGim8TNvZw/76HhabH4rNWbakWliERcr7jRc1LgUbNGf2mHUlde8lvg0ruk…
selectors probed - selector1:
Certificate (current)
E8
Expires in 43 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src https://videos.ctfassets.net 'self' 'unsafe-inline'; img-src https://www.googletagmanager.com https://www.google-analytics.com https://downloads.ctfassets.net https://images.ctfassets.net https://px4.ads.linkedin.com https://px.ads.linkedin.com data: 'self'; script-src https://www.googletagmanager.com https://cdn.cookiehub.eu https://snap.licdn.com 'self' 'unsafe-inline' 'unsafe-eval'; connect-src https://consent.cookiehub.net https://*.google-analytics.com https://www.googletagmanager.com https://hgcapital.pinpointhq.com https://downloads.ctfassets.net https://graphql.contentful.com https://vimeo.com https://lensflare.vimeo.com https://px.ads.linkedin.com https://region1.google-analytics.com 'self'; style-src https://cookiehub.net 'self' 'unsafe-inline'; object-src 'none'; frame-src https://forms.hgcapital.com https://player.vimeo.com; frame-ancestors 'none'- strict-transport-security
max-age=31536000; includeSubDomains; preload