leawood.org

.org crawl

First seen 2026-05-02 · Last seen 2026-05-09 · ok HTTP/1.1 200 3419 ms crawled 2026-05-09

NL · 89.106.200.1 · AS209626 Enflow B.V.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Leawood, KS | Official Website
Language
en

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • app-script.monsido.com×2
  • docaccess.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone

Registration

Registrar
Network Solutions, LLC
Created
1997-04-18
Expires
2031-04-19 1795 days left
Updated
2026-02-23
Name servers
  • ns3.level3.net
  • ns4.level3.net

DNS records live

NS
  • ns3.level3.net
  • ns4.level3.net
MX
  • 10 leawood-org.mail.protection.outlook.com
TXT
Show 6 TXT records
  • MS=ms44984482
  • cisco-ci-domain-verification=2709fcc2f3344858c8c3604597008ff342e5a0dda15f819b2836d84ec764abc3
  • google-site-verification=xU59-wAHlLXp0F5oROTV_EO-jypaKNIb5XnCT48vg7U
  • MS=D4B69A0BC32AE35B93A54709697B90989EA6A265
  • apple-domain-verification=IiL0P5jFgKDYkVxw
  • v=spf2 mx ip4:69.71.62.18 -all

Email authentication weak

SPF
v=spf1 mx ip4:69.71.62.18 include:spf.protection.outlook.com -all
strict (-all)
DMARC
not published
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

E7
from 2026-04-07 to 2026-07-06
Expires in 47 days

HTTP security headers

Header hygiene 50/100 Checked live page: https://www.leawood.org

present
  • content-security-policy
  • x-content-type-options
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
frame-ancestors 'self' https://*.granicus.com https://platform.civicplus.com https://account.civicplus.com https://analytics.civicplus.com; img-src * data: blob:; worker-src * data: blob: 'unsafe-eval' 'unsafe-inline'; script-src * about: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; media-src * blob:; font-src * data:; default-src *

Links to (8)

Linked from (1)