jfcu.org
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (9)
- integration.silvercloudinc.com×2
- maxcdn.bootstrapcdn.com×2
- www.googletagmanager.com×2
- ajax.googleapis.com×1
- cdn.agentbot.net×1
- cdnjs.cloudflare.com×1
- code.jquery.com×1
- fonts.googleapis.com×1
- www.youtube-nocookie.com×1
Contact
- Phone
- Address
- 800.550.5328jfcu@jfcu.orgJustice Federal Credit Union 5175 Parkstone Drive, Suite 200 Chantilly, VA 20151ABA/Routing Number:254074413
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1997-09-02
- Expires
- 2028-09-01 836 days left
- Updated
- 2025-07-08
- Name servers
-
- ns71.worldnic.com
- ns72.worldnic.com
DNS records live
- NS
-
- ns71.worldnic.com
- ns72.worldnic.com
- MX
-
- 10 jfcu-org.mail.protection.outlook.com
- TXT
-
Show 15 TXT records
8hac2rkngutu7gd0fuf4do5uklbmi4h1fnj1t2a2afogufau3i754d19ee75-fa98-45d1-8685-22c22f1a1f79tim14ua3onifhteplvsr0v7khfp53s2avq3cf0sggolk9bphbo8acv26mungmg6sh49t4f1e0ss1lpadobe-sign-verification=e853643323a76bb876188f9f51b1a3bdq2ehf8hf171n76gbv849mi4bcpcb5390d73miesogg2qsed10ir179fm83i2tfq33f4hd0ueuf33qrMS=ms95192647gcp6mdhi58i5g663641nj2hu9iapple-domain-verification=iiYgg1vQ88czOdwT9c87d3a3-a1f6-456a-ba0e-666fee89dab875eg68tbkfbgpfmbebg7v9llkt
Email authentication strong
- SPF
-
v=spf1 ip4:4.37.224.192/26 ip4:4.39.89.192/26 ip4:4.39.177.64/27 ip4:98.173.138.64/26 ip4:66.118.90.128/27 ip4:199.233.227.58 ip4:199.233.227.59 ip4:199.233.227.60 ip4:199.233.227.61 include:spfref.jackhenry.com include:docs-center.com include:jfcu-org.spf.smtp25.com include:spf.protection.outlook.com include:mktomail.com include:spfus.doxim.com include:_external.pscu.com a:_mailhosts.swbc.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@jfcu.org; ruf=mailto:dmarc_ruf@jfcu.org;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtJy+gyrqnUUtISMzAyYJ+T2Fw51wnwul1UrMLS3xaDQ3DiSj6idUvq6/YjJEu0xpmXLHNcoWuNUZTe…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 158 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; frame-ancestors 'none';- strict-transport-security
max-age=31536000; includeSubDomains; preload