marathonus.com
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×5
- fonts.gstatic.com×1
- maps.googleapis.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- 4525 Columbus St Suite 200, 23462, Virginia Beach, VA
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2006-01-19
- Expires
- 2029-01-19 976 days left
- Updated
- 2024-01-19
- Name servers
-
- ns1-06.azure-dns.com
- ns2-06.azure-dns.net
- ns3-06.azure-dns.org
- ns4-06.azure-dns.info
DNS records live
- NS
-
- ns1-06.azure-dns.com
- ns2-06.azure-dns.net
- ns3-06.azure-dns.org
- ns4-06.azure-dns.info
- MX
-
- 0 marathonus-com.mail.protection.outlook.com
- TXT
-
v=spf1 include:mailgun.org include:spf.protection.outlook.com include:servers.mcsv.net -allMS=ms39137104atlassian-domain-verification=S2qgjPXPpiI7AAHQRlc5nI7GI47QrEbcsruiHCFX3eUZV1t0uaWhlFwCyHmx-QlF
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 93 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.discus.com/ *.discuscdn.com/ *.gstatic.com/ *.gravatar.com/ dashboard.umbraco.com/;connect-src 'self' wss://localhost:* ws://localhost:* http://localhost:* stats.g.doubleclick.net/j/ www.google-analytics.com/ *.disquscdn.com/ disqus.com/ *.disqus.com/ *.hotjar.com/ wss://ws3.hotjar.com/api/ *.clarity.ms/ *.googleapis.com/ *.gstatic.com/ *.gravatar.com/ dashboard.umbraco.com/ *.linkedin.oribi.io/ *.google.com/ccm/ *.bing.com/ *.ads.linkedin.com/ *.google.com/pagead/;font-src 'self' data: fonts.googleapis.com/ maxcdn.bootstrapcdn.com/ fonts.gstatic.com/ *.disquscdn.com/ *.gstatic.com/ *.gravatar.com/;frame-src 'self' www.googletagmanager.com/ www.google.com/recaptcha/ www.facebook.com/tr/ disqus.com/ *.disqus.com/ *.hotjar.com/ *.youtube.com/ *.gstatic.com/ *.gravatar.com/ dashboard.umbraco.com/ *.libsyn.com/;child-src www.youtube.com/ *.gravatar.com/;img-src 'self' data: blob: *.vimeocdn.com www.facebook.com/ www.google-analytics.com/ stats.g.doubleclick.net/r/ www- strict-transport-security
max-age=63072000; includeSubDomains