lutheranworld.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Drupal
Third-party hosts loaded (1)
- static.addtoany.com×1
Social
Contact
- Phone
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 1997-05-13
- Expires
- 2027-05-14 359 days left
- Updated
- 2026-03-09
- Name servers
-
- dean.ns.cloudflare.com
- shaz.ns.cloudflare.com
DNS records live
- NS
-
- dean.ns.cloudflare.com
- shaz.ns.cloudflare.com
- MX
-
- 1 lutheranworld-org.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
apple-domain-verification=C2lDDarKYwerlvbed9573c0e-281f-4eda-ae5d-a6d62636ed0cdocusign=69c5fecc-a991-41cd-9456-373382588891protonmail-verification=fcf37b9d08874b515f7631b924e9158639805761MS=ms81775045T/fSkCcYOTDI2izMl81xNi1aDDep+kcWvKuixyQQYlKbwCphcm/9nLS2rELvwJdoY/aLEuR21SfAx0JXzjtmDQ==anthropic-domain-verification-4cnfg5=a9uQnM0H8RntoqWri8dIELoRj
Email authentication strong
- SPF
-
v=spf1 mx ip4:193.73.242.0/24 ip4:54.228.196.38/32 ip4:85.222.158.192/28 include:_spf.odoo.com include:spf.protection.outlook.com include:spf.event-works.com include:spf.mandrillapp.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:service.desk@lutheranworld.org; fo=1; adkim=r; aspf=r; pct=100; rf=afrf; ri=86400policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsWrHVa5Eu1wi+DEfbefn8g5qKtaCNMhpROOfzgBRS/6gWCjdCM/PiB8n7FtzVw859qCSAgvpPfKbEl… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA07V8csO/ccHIxUHW6E2pLH2KfO9MMXz5mKoimRu7f5IlpTwojH7EJ6LfcD1dQ5/+ern7Hr8zmBLpgm… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 64 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' https://www.google-analytics.com https://*.google-analytics.com https://embedr.flickr.com https://www.googletagmanager.com; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com; frame-src 'self' https://static.addtoany.com https://www.google.com https://www.youtube.com https://vimeo.com https://player.vimeo.com https://view.genial.ly https://www.facebook.com https://app.recruiterbox.com https://w.soundcloud.com https://www.podbean.com https://embed.podcasts.apple.com https://open.spotify.com; img-src 'self' data: https://www.google-analytics.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://live.staticflickr.com/ https://w.recruiterbox.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://embedr.flickr.com https://widgets.flickr.com https://w.recruiterbox.com cdn.jsdelivr.net https://cdn.jsd