hstpathways.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Font Awesome
Third-party hosts loaded (4)
- use.fontawesome.com×3
- cdn-cookieyes.com×1
- px.ads.linkedin.com×1
- www.googletagmanager.com×1
Social
Contact
- Address
- 3102 West End Ave Suite 400, 37203, Nashville, TN, US
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2006-02-15
- Expires
- 2027-01-05 230 days left
- Updated
- 2026-01-06
- Name servers
-
- ns-1301.awsdns-34.org
- ns-1537.awsdns-00.co.uk
- ns-206.awsdns-25.com
- ns-585.awsdns-09.net
DNS records live
- NS
-
- ns-1301.awsdns-34.org
- ns-1537.awsdns-00.co.uk
- ns-206.awsdns-25.com
- ns-585.awsdns-09.net
- MX
-
- 10 mx1-us1.ppe-hosted.com
- 20 mx2-us1.ppe-hosted.com
- TXT
-
Show 16 TXT records
logmein-verification-code=d2c02dd6-8eb0-450a-8726-e8203817922cpardot944953=4a21bfd96ae8d6487dddedde25a71766f6ec4e09443a23646b375112bed2cdc5pendo-domain-verification=bd2ee910-df05-47a3-9890-243a957defd9phvk9936k0f00m1gf68sf7vlz0q2wscvqgl7hs3bxqkz3p3psbhbpw0fcsj9dxrksmartsheet-site-validation=KVNTCYYlDtkYRfZZ8qUIAA3-j6aNqTQgvmw782nym1n415rlnq8x1vx68vdrx6rq03pl0mjrfxqnlp6932tyhnplqt43rm8s5906ABA786MS=ms37251181ZAC1836anthropic-domain-verification-1errhj=49nN4wUoEkIcZEmL4bny9M28Dapple-domain-verification=o0lWWroSA95fA4o0atlassian-domain-verification=tfCCZxCm9iNcmYSFTU2b+mSLCG/dCeoSO08zI4yWsQwizZ79OGait5YYnVJhDYFHbryhctwby6567575pkszqn7gl7j4fm9ncursor-domain-verification-qba9y1=aRvzXRJDZJnW0HbLpwrWKC1fo
Email authentication strong
- SPF
-
v=spf1 a mx a:dispatch-us.ppe-hosted.com include:_spf.salesforce.com include:amazonses.com include:sendgrid.net Include:_spf.highradius.com ip4:207.223.114.15 include:_spf.psm.knowbe4.com include:relay.mailchannels.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@hstpathways.com; ruf=mailto:dmarc-reports@hstpathways.com;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDdfepv0Ay8OTCUgxostA8E8oDhdOj1s3o9Q+U35H0AU+S5/6lqwB1ah5DEgjMSawsTMKBpK5DawHHucTa6Zy…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 58 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), midi=(), sync-xhr=(), microphone=(), camera=(), magnetometer=(), gyroscope=(), fullscreen=(self), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https: data:; connect-src 'self' wss://*.tawk.to wss://ws.hotjar.com https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:;- strict-transport-security
max-age=31536000; includeSubDomains; preload