hmg.com
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- cdnjs.cloudflare.com×13
- cdn.jsdelivr.net×4
- www.googletagmanager.com×2
- code.jquery.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1993-12-15
- Expires
- 2027-12-14 573 days left
- Updated
- 2022-12-04
- Name servers
-
- ns1.itc.net.sa
- ns2.itc.net.sa
DNS records live
- NS
-
- ns1.itc.net.sa
- ns2.itc.net.sa
- MX
-
- 10 mail.hmg.com
- 10 mail.marketing.hmg.com
- TXT
-
Show 14 TXT records
google-site-verification=TrH6nvnOJoIQYf_Dgf09ICIrQEH91bWN-trrj8J8nmIDlrBaWOhGpahiTeZquAyRRAOtSY8C27d6ahIMqj9X9l5w5WX8aAhKaws5N9QOgnS_35bt7beqxt4e2x2b974yhyw364kcq3o_kd0nz41z7ohbazy877csvyu8a7c7e5bchc2p9zvdzjvjwvzdj7pp2s8ggpfcxp03733gd1k9m4g4lbvvxfm91zgjn1vgqxmgoogle-site-verification=r22gSX_PGx7YLDZ8W-rVJkCRU5JioC5YR0zwKv-gr7Uaadbf4c24e984946bed9b5c94dc0c0b2ljk2lzkmszxzqgb4pgg7m1yyd3wxknjcatlassian-domain-verification=DlrBaWOhGpahiTeZquAyRRAOtSY8C27d6ahIMqj9X9l5w5WX8aAhKaws5N9QOgnSgoogle-site-verification=Tq-Y-YiT7l8ZGgffApEzvlHKeGl4YtKp4B0kVDRJ0mY_3hdu6vh8qdt37ur46joslv7ydvk5k6yfp4xrj4cd5xpgl0k03ngv6cc6qdl5bq0fnylvz4km2f9dmgr4hcq1f518rzh5tfq
Email authentication partial
- SPF
-
v=spf1 mx a:mail.hmg.com a:mail.cloudsolution-sa.com a:mail.shi.sa a:mail.mdlaboratories.com a:mail.hmg.com.sa a:mail.alajajidental.com a:drsulaimanalhabib.com ip4:87.101.131.11 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com,mailto:haseen@rua.dmarc.gov.sa; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com,mailto:haseen@ruf.dmarc.gov.sapolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 32 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com;, object-src 'none'- strict-transport-security
max-age=31536000