mcmurrayhatchery.com
HTML metadata
Technology
- Server
- nginx
- jQuery
- 3.5.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×2
- mcmurrayhatchery.refersion.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- NameCheap, Inc.
- Created
- 1996-09-17
- Expires
- 2027-09-16 467 days left
- Updated
- 2022-09-01
- Name servers
-
- dns1.easydns.com
- dns2.easydns.net
- dns3.easydns.org
- ns0.dnsmadeeasy.com
- ns1.dnsmadeeasy.com
- ns2.dnsmadeeasy.com
- ns3.dnsmadeeasy.com
- ns4.dnsmadeeasy.com
DNS records live
- NS
-
- ns0.dnsmadeeasy.com
- ns1.dnsmadeeasy.com
- ns2.dnsmadeeasy.com
- ns3.dnsmadeeasy.com
- ns4.dnsmadeeasy.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification:MtBBz2r_8W4HhP_qRuuS4PCufNt67JalMPfMUD3quBI
- Verified for
-
- Atlassian
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net a:mcmurrayhatchery.com a:otr.hatcherymgr.com mx:mcmurrayhatchery.com ip4:208.69.147.197 ip4:138.197.1.210 ip4:138.197.1.204 ip4:104.131.49.162 ip4:104.248.13.22 ip4:12.215.246.242 ip4:97.105.124.126 ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:39c0ed18aa@rua.easydmarc.us;ruf=mailto:39c0ed18aa@ruf.easydmarc.us;fo=1;pct=100;adkim=r;aspf=rpolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAiDZHPvTAlAseZitmHYXOmd5xNONlxKADKgPUJTm7GMi6SPIfXdxwvZ/b4COhFgnBxO9LbIlHT6Jhnd… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - google:
Certificate (current)
R13
Expires in 23 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src https: 'self' *.mcmurrayhatchery.com www.youtube.com api.instagram.com; script-src https: 'self' *.mcmurrayhatchery.com www.youtube.com api.instagram.com 'unsafe-inline' *.google-analytics.com platform.twitter.com cdn.syndication.twimg.com mcmurrayhatchery.refersion.com 'unsafe-eval' *.mcmurrayhatchery.com; style-src https: 'self' *.mcmurrayhatchery.com www.youtube.com api.instagram.com 'unsafe-inline' ton.twimg.com platform.twitter.com fonts.googleapis.com; font-src https: 'self' *.mcmurrayhatchery.com www.youtube.com api.instagram.com fonts.gstatic.com fonts.googleapis.com; img-src https: 'self' *.mcmurrayhatchery.com www.youtube.com api.instagram.com blob: data: *.google-analytics.com *.gstatic.com *.googletagmanager.com *.twitter.com *.twimg.com *.cloudfront.net scontent.cdninstagram.com www.paypal.com; frame-ancestors 'none';- strict-transport-security
max-age=31536000; includeSubDomains; preload