mainestatecu.org
HTML metadata
Technology
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- use.typekit.net×3
- api.glia.com×1
- embed.signalintent.com×1
- wt.dm00.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- rd of Directors & Senior ManagementEventsNewsCareersAnnual ReportsContact Us800-540-87072
DNS records live
- NS
-
- dns101.register.com
- dns102.register.com
- MX
-
- 0 mx2-us1.ppe-hosted.com
- 5 mx1-us1.ppe-hosted.com
- TXT
-
Show 16 TXT records
MS=ms75370138S0Y1N24351h984jgqhuvkalk94ms9dv4al64huisrroqodgmv58vmreneebb3dapple-domain-verification=i9pOXXQZeC1gx0so9abk1kvj48id4n5642k18q30nkmn1m0q2k7ufgptkvj9ica48eumhn7biloglt0hqahepuoi1gfmurgoogle-site-verification=KH6hURToyEWNbkBh4bwcNLpm2S2SUAxHXdI6KKN-6zAciscocidomainverification=42e2bebf28893213ede1069d270954677f65d89d22bba39e6577e6a89cffd17cisco-ci-domain-verification=42e2bebf28893213ede1069d270954677f65d89d22bba39e6577e6a89cffd17l33hspqe4aao09atf6s94mblkbd2ebeaf7m3pp6v98liquh6l7u5ol7&xiuoD2nmkaOpM8zkPUayHyFp$^tRXfiCU6d8b@D33#ZJVFy$14DFDOh0b8y0w733pEGhtgV23KGavQwvabl5gYQhvk$tUZAatlassian-domain-verification=3of1j9bbI6nZBgU49taWbaZbiLydZMb96GcCns5QCn83fxN3kptA6IiC9pNfW5Dq4yd4wjpwz9r931lv9xzh198m6ywl39s0
Email authentication strong
- SPF
-
v=spf1 include:3gt9ptenr3.powerspf.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:9kgqiype09@rua.powerdmarc.com; ruf=mailto:9kgqiype09@ruf.powerdmarc.com; fo=1;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 278 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
geolocation=(), midi=(), sync-xhr=(), accelerometer=(), gyroscope=(), magnetometer=(), payment=(), camera=(), microphone=(), usb=(), xr-spatial-tracking=(), fullscreen=(self)- x-content-type-options
nosniff, nosniff- content-security-policy
default-src https://* 'unsafe-inline' data:; script-src https: 'unsafe-inline' 'unsafe-eval' blob:; worker-src blob: 'self'; child-src blob: 'self' https://www.googletagmanager.com; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://cdn.userway.org/ https://www.youtube.com; connect-src https: wss: 'self'; img-src https://* data:;- strict-transport-security
max-age=63072000; includeSubdomains; preload
Links to (11)
- apple.com×1
- facebook.com×1
- google.com×1
- instagram.com×1
- linkedin.com×1
- loanspq.com×1
- swivelpay.com×1
- tiktok.com×1
- userway.org×1
- x.com×1
- youtube.com×1