leonards.com
HTML metadata
Technology
- Server
- Apache
- CMS
- Next.js
Third-party hosts loaded (3)
- cdnjs.cloudflare.com×3
- static.zdassets.com×1
- v2.zopim.com×1
Social
Registration
- Registrar
- Wild West Domains, LLC
- Created
- 1996-08-20
- Expires
- 2026-08-01 60 days left
- Updated
- 2024-08-01
- Name servers
-
- ns11.constellix.com
- ns21.constellix.com
- ns31.constellix.com
- ns41.constellix.net
- ns51.constellix.net
- ns61.constellix.net
DNS records live
- NS
-
- ns11.constellix.com
- ns21.constellix.com
- ns31.constellix.com
- ns41.constellix.net
- ns51.constellix.net
- ns61.constellix.net
- MX
-
- 10 mail.leonards.com
- 20 mail1.leonards.com
- TXT
-
ynwhlgnp6r61ftb4z16l6k2qp6f5vdmm
- Verified for
-
- Apple
- Brevo
Email authentication strong
- SPF
-
v=spf1 ip4:12.226.226.248/29 ip4:50.206.198.176/29 ip4:50.240.112.112/29 include:mail.zendesk.com include:_spf.psm.knowbe4.com include:mailgun.org include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:ryan@leonards.com; ruf=mailto:ryan@leonards.com; fo=1; adkim=r; aspf=rpolicy: quarantine - DKIM
-
Show 5 DKIM selectors
- default:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCvuRWUJEGgxHuNYHkyRWqwM0KPgBoMOl2hVl12JUlQbbU6cWQH8bQ8x2FN2rG0E6cJXeo3bWlHTC5mjUbASEEs7VqIuvX… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - mail:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyS2spWBSG3yLbq3NXPAvpKQSAAahMzIQtprgGmC2GEU/Fst1yVB4oG10ITdPCFiMmzsZCGzo033tlrfEHnSFZ… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyGD7cfF2PnNpNWWeJpTqBa3whqnrROAilBiylg7tF8cTH/xVO5/cU6txJoayd1YhcV69UoyjAJ8PDz9laE… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDSbRPnlAGQENG1atgd5NOV2Ad5akkmabZ/B6X1pep4LpexZ5Mfjm0sj0xjR+fVHJEGeav5rtlVyWi88Ijb6PH2Wq…
selectors probed - default:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 85 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
Header values
- x-frame-options
DENY- permissions-policy
geolocation=(), microphone=(), camera=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://v2.zopim.com https://ekr.zdassets.com https://static.zdassets.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com blob:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; connect-src 'self' https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://www.leonards.com https://leonards.com https://sa-test.leonards.com https://schooladmin.leonards.com https://maps.googleapis.com https://v2.zopim.com https://ekr.zdassets.com https://itsupport-dst0f.zendesk.com https://graph.instagram.com wss://widget-mediator.zopim.com https://issuu.com; font-src 'self' https: data:; frame-ancestors 'none'; base-uri 'self'; form-action 'self';- strict-transport-security
max-age=31536000; includeSubDomains; preload