jfa-aviation.com

.com crawl

First seen 2026-04-18 · Last seen 2026-05-09 · ok HTTP/1.1 200 1287 ms crawled 2026-05-12

US · 172.66.0.42 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Top Jet Brokerage in Fort Lauderdale - JFA Aviation Sales
Description
Explore premium aircraft brokerage services with JFA Aviation in Fort Lauderdale. Specializing in jet sales and acquisitions, we ensure seamless transactions.
Language
en

Open Graph

url
https://jfa-aviation.com/
title
Top Jet Brokerage in Fort Lauderdale - JFA Aviation Sales
description
Explore premium aircraft brokerage services with JFA Aviation in Fort Lauderdale. Specializing in jet sales and acquisitions, we ensure seamless transactions.

Technology

CDN
Cloudflare
CMS
Next.js
Analytics
  • Cloudflare Insights

Third-party hosts loaded (2)

  • cdn.durable.co×3
  • static.cloudflareinsights.com×1

Registration

Registrar
GoDaddy.com, LLC
Created
2025-06-28
Expires
2028-06-28 770 days left
Updated
2025-06-28
Name servers
  • ns17.domaincontrol.com
  • ns18.domaincontrol.com

DNS records live

NS
  • ns17.domaincontrol.com
  • ns18.domaincontrol.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • google-site-verification=xDEc4VPFJA3yk9LiUl4vdSn8UvU0Df0RDqIxOE6SFA0

Email authentication strong

SPF
v=spf1 include:dc-aa8e722993._spfm.jfa-aviation.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net;
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

WR1
from 2026-04-24 to 2026-07-23
Expires in 64 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://jfa-aviation.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
Header values
referrer-policy
origin
x-frame-options
ALLOWALL
permissions-policy
fullscreen=*
x-content-type-options
nosniff
content-security-policy
default-src * data: blob: http: https: 'self' https://*.durable.co https://*.durable.com 'unsafe-inline' *.durable.co *.durable.com 'unsafe-eval';
strict-transport-security
max-age=15552000; includeSubDomains
cross-origin-opener-policy
cross-origin
cross-origin-embedder-policy
unsafe-none
cross-origin-resource-policy
cross-origin

Links to (1)

Linked from (1)