massagetables.com
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- oakworks.sirv.com×39
- www.googletagmanager.com×2
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1996-12-06
- Expires
- 2032-12-05 2391 days left
- Updated
- 2025-05-13
- Name servers
-
- pdns01.domaincontrol.com
- pdns02.domaincontrol.com
DNS records live
- NS
-
- pdns01.domaincontrol.com
- pdns02.domaincontrol.com
- MX
-
- 0 massagetables-com.mail.protection.outlook.com
- TXT
-
google-site-verification=9zKL-slvejkrrzPzfago6dMP_xaFWZBOSgcm2oYo8qo
Email authentication weak
- SPF
-
v=spf1 ip4:72.23.112.32/27 include:spf.protection.outlook.com include:spf-us.emailsignatures365.com ip4:204.140.21.19 ip4:204.140.21.20 mx:oakworks.com include:spf.constantcontact.com include:ccsend.com a -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv4WRL7FMQ/KE/9Thprx8CqGHew90WEVk/XOwkeClrJFGruxoQgo+ORT9goUFYFSF56fe78wQg0Uy/p…
selectors probed - selector1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 16 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.massagetables.com *.spatables.com https://www.google.com/measurement/conversion *.smartystreets.com https://q.clarity.ms/collect https://s3-us-west-2.amazonaws.com/mfesecure-public/host/massagetables.com/* https://s3-us-west-2.amazonaws.com/mfesecure-public/* https://s3-us-west-2.amazonaws.com/mfesecure-public/host/www.massagetables.com/* https://s3-us-west-2.amazonaws.com/mfesecure-public/host/www.massagetables.com/client.json stats.g.doubleclick.net www.mcafeesecure.com cdn.ywxi.net analytics.google.com www.google-analytics.com google-analytics.com ajax.googleapis.com fonts.googleapis.com *.paysimple.com; style-src data: 'unsafe-inline' *.massagetables.com *.paysimple.com oakworks-cdn.sirv.com oakworks.sirv.com cdn.ywxi.net cdnjs.cloudflare.com www.google.com www.gstatic.com www.googletagmanager.com fonts.googleapis.com ssl.p.jwpcdn.com; img-src 'self' data: *.massagetables.com www.googletagmanager.com oakworks.sirv.com oakworks-cdn.sirv.com www.google-analytics- strict-transport-security
max-age=31536000