lakeshorepbs.org

.org crawl

First seen 2026-05-29 · Last seen 2026-06-01 · ok HTTP/1.1 200 1266 ms crawled 2026-05-31

US · 52.33.207.7 · AS16509 Amazon.com, Inc.

Reputation 87/100 weak security headers no dmarc policy

Classifying

HTML metadata

Title
Lakeshore PBS | Passport
Description
Get extended access to thousands of full episodes and award-winning films. Stream top food shows, dramas, histories, documentaries, and more.
Language
en

Technology

Server
openresty
CMS
Next.js
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • image.pbs.org×51
  • www.googletagmanager.com×1

DNS records live

NS
  • curitiba.ns.porkbun.com
  • fortaleza.ns.porkbun.com
  • maceio.ns.porkbun.com
  • salvador.ns.porkbun.com
MX
  • 0 mail1.filteredmx.net
  • 0 mail2.filteredmx.net
  • 0 mail3.filteredmx.net

Email authentication weak

SPF
v=spf1 ip4:50.115.20.55 include:spf.filteredmx.net +a +mx ~all
softfail (~all)
DMARC
not published
DKIM
  • default: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuPVBNLDyX55VQ5lJ7p0Zp88xg5vd4axCEUffB0hnBPkcUd9v8k+2RwrsdTmI9EHRdxsAWZrmZFgbKh…
selectors probed

Certificate (current)

R12
from 2026-05-06 to 2026-08-04
Expires in 64 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://video.lakeshorepbs.org/passport/learn-more/?_gl=1*4qmas8*_ga*NTIxNTQ0NzIzLjE3MDk2NzM5MTg.*_ga_RF0WP2VN4Q*czE3NTg1NDg3MDMkbzg0MiRnMSR0MTc1ODU0ODc2NCRqNjAkbDAkaDA.

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self' *.pbs.org; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.pbs.org *.googlesyndication.com *.adtrafficquality.google adservice.google.com adservice.google.co.in connect.facebook.net fundingchoicesmessages.google.com *.2mdn.net *.nr-data.net sb.scorecardresearch.com securepubads.g.doubleclick.net www.google-analytics.com analytics.google.com www.googletagmanager.com *.googletagservices.com 'unsafe-inline' 'unsafe-eval' *.cookielaw.org www.redditstatic.com alb.reddit.com analytics.tiktok.com s.pinimg.com *.ketchcdn.com *.ketchjs.com static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' *.pbs.org *.ketchcdn.com *.ketchjs.com; img-src 'self' blob: data: *.pbs.org *.doubleclick.net *.cookielaw.org *.googlesyndication.com *.adtrafficquality.google sb.scorecardresearch.com www.googletagmanager.com www.facebook.com graph.facebook.com platform-lookaside.fbsbx.com *.2mdn.net *.agkn.com *.fbsbx.com *.fbcdn.net www.google-analytics.com www.google.com *.googleusercont

Links to (2)

Linked from (2)