iffr.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (2)
- static.queue-it.net×2
- consent.cookiebot.com×1
Social
Registration
- Registrar
- NextName B.V.
- Created
- 2000-06-06
- Expires
- 2026-06-06 17 days left
- Updated
- 2025-06-07
- Name servers
-
- carol.ns.cloudflare.com
- dave.ns.cloudflare.com
DNS records live
- NS
-
- carol.ns.cloudflare.com
- dave.ns.cloudflare.com
- MX
-
- 1 smtp.google.com
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:servers.mcsv.net include:eu.mailgun.org include:spf.mandrillapp.com ip4:213.127.198.56/29 ip4:37.139.12.89 ip4:188.226.190.156 ip4:188.226.178.19 ip4:37.139.3.98 ip4:188.226.158.113 ip4:128.199.37.231 ip4:198.199.127.234 ip4:192.81.223.80 ip4:37.247.40.64 ip6:2001:4c10:1:220::31 include:_spf.shared.lvl.li ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=quarantine; sp=quarantine;pct=100;rua=mailto:dmarc-rua@iffr.com;ruf=mailto:dmarc-ruf@iffr.com;ri=86400;aspf=s;adkim=s;fo=0:1:d:spolicy: quarantine · sp=quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAgNF1RIWZbpok7g5rzsZBVTrNXpdi7n1c9HdKER6vs0Fa3CqktUzJrDa8cIirreSl5X0xcAZ7AbLC6y… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6dtYINfT7KlhSxM1JJDAX5EeOuzTDiHs+Wvp0uEfIEpI3G6C01sYYasNiMtL4Ci32l/l4Xrao3B0FeehbxdOrwBnGee4…
selectors probed - google:
Certificate (current)
E8
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src https: data: blob:; script-src 'unsafe-inline' 'unsafe-eval' https: data:; style-src 'unsafe-inline' https: data:; img-src data: https: blob: android-webview android-webview-video-poster:; font-src data: https:; connect-src * data:; media-src https: data: blob:; worker-src https: blob:; frame-src 'self' https: blob:; frame-ancestors 'self'; upgrade-insecure-requests- strict-transport-security
max-age=63072000