mainaccount.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-14 · ok HTTP/1.1 200 1046 ms crawled 2026-05-07

US · 170.61.53.24 · AS8012 The Bank of New York Mellon Corporation

Reputation 100/100

Classifying

Registration

Registrar
MarkMonitor Inc.
Created
1999-10-07
Expires
2026-10-07 140 days left
Updated
2024-09-05
Name servers
  • seth.ns.cloudflare.com
  • zoe.ns.cloudflare.com

DNS records live

NS
  • seth.ns.cloudflare.com
  • zoe.ns.cloudflare.com
MX
  • 10 mxa-00157d02.gslb.pphosted.com
  • 10 mxb-00157d02.gslb.pphosted.com

Email authentication strong

SPF
v=spf1 include:spf-00157d02.pphosted.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

DigiCert Global G2 TLS RSA SHA256 2020 CA1
from 2026-02-13 to 2027-03-17
Expires in 301 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://mainaccount.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' *.albridge.com:* *.bnymellon.net *.cirstatements.com *.mainaccount.com *.woveplatform.com *.vidyard.com *.morningstar.com *.byallaccounts.net cdn.cookielaw.org *.onetrust.com *.gstatic.com blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.morningstar.com *.polyfill.io *.jsdelivr.net ajax.googleapis.com cdnjs.cloudflare.com *.cirstatements.com *.mainaccount.com *.woveplatform.com *.google.com *.gstatic.com *.bnymellon.net *.highcharts.com *.vidyard.com *.newrelic.com *.byallaccounts.net cdn.cookielaw.org *.onetrust.com; style-src 'self' 'unsafe-inline' *.morningstar.com *.bnymellon.net *.cirstatements.com *.mainaccount.com *.woveplatform.com *.vidyard.com *.byallaccounts.net *.googleapis.com; img-src 'self' data: *.albridge.com *.bnymellon.net *.bnymellon.com *.cirstatements.com *.mainaccount.com *.woveplatform.com *.schwab.com *.vidyard.com cdn.cookielaw.org *.onetrust.com *.byallaccounts.net blob:; frame-src 'self' *.cirstatements.com *.mainaccount.com *.wove
strict-transport-security
max-age=15768000;includeSubDomains

Linked from (6)