merchantsandfarmers.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- ajax.googleapis.com×1
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Register.com - Network Solutions, LLC
- Created
- 1997-01-28
- Expires
- 2032-01-29 2079 days left
- Updated
- 2024-04-10
- Name servers
-
- ns1.jh-cf.com
- ns2.jh-cf.com
DNS records live
- NS
-
- ns1.jh-cf.com
- ns2.jh-cf.com
- MX
-
- 0 merchantsandfarmers-com.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
duo_sso_verification=VkGLxmFWf6uf4XLGHeud2asSDeZd8rFD8zkOBcndeJaWS5TN4uzOXjQ2Lp5k8ZzNe2ma-verification=gj4abp1b45nybqrh7yvd76990pbp61829gjfksb1wff5brhwg5fbmkbxfsyt13k9w3b98
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf2.merchantsandfarmers.com include:spf.protection.outlook.com include:spfref.jackhenry.com include:mailgun.org ip4:66.45.26.197 ip4:208.82.208.0/22 ip4:63.236.8.128/26 ip4:63.150.172.128/27 ip4:208.185.229.0/24 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantinepolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9+MxTHKjzCkZYlXHXgBHkS93R3Ca2O3xBIRZvnObCpPoiNX9OKdH9OcTZueMOfaCzkyYFj9RtxdBntx+OIh…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 41 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' crownpeak.net *.crownpeak.net *.googleapis.com *.google.com *.google-analytics.com *.gstatic.com data: blob:; font-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com; frame-ancestors 'self'; frame-src 'self' *.youtube.com *.google.com *.vimeo.com *.paymentsemails.com; img-src 'self' *.google-analytics.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.placeholder.com data:; media-src 'self'; script-src 'self' 'unsafe-inline' *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com banno.com *.banno.com crownpeak.com *.crownpeak.com; style-src 'self' 'unsafe-inline' *.googleapis.com- strict-transport-security
max-age=16070400