mercyforanimals.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
Third-party hosts loaded (1)
- cloud.typography.com×1
Social
Contact
- Phone
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2002-04-02
- Expires
- 2028-04-02 682 days left
- Updated
- 2026-05-17
- Name servers
-
- clyde.ns.cloudflare.com
- leah.ns.cloudflare.com
DNS records live
- NS
-
- clyde.ns.cloudflare.com
- leah.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 9 TXT records
MS=37F1AE3D7F8A6DCC849419844FF96C3BD030DC28logmein-verification-code=d5434fb7-703d-4c1c-9e24-a6fd82ab5936fantomo=xsr9HWHjhkvYuaXXNARBFhoisZu2ywProbely=3476b476-b0a7-4c7e-bd35-968f8b0c4153have-i-been-pwned-verification=511f8b685e0b7bd8389f0e841b470b5flogmein-verification-code=8ca20565-804f-495f-9802-61ea34c6947f1b41de7a7687e3af176aa2f9a746623e0e4280074ba4107c46538c214779ed66sending_domain939853=94a91ac4ca5bafdb411f241d3b2d3708d7698c15394b968644840b0b66cf91d8nordpass-domain-verification=e88b11dc35ab4b40bc0fed6c24d34578
- Verified for
-
- Apple
- Atlassian
- Canva
- Figma
- Microsoft 365
- OpenAI
- Stripe
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:_spf.salesforce.com include:aspmx.pardot.com include:70926872.agenciapr.net include:mg-spf.greenhouse.io ip4:192.254.121.248 include:outboundmail.convio.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; fo=1; ri=3600; rua=mailto:f09688cfd7e44560b9a7f0fffc4a634b@dmarc-reports.cloudflare.net,mailto:a12a9dd4@inbox.ondmarc.com,mailto:f98c252f@in.mailhardener.com,mailto:s2a2b9xdf8@rua.powerdmarc.com; ruf=mailto:a12a9dd4@inbox.ondmarc.com,mailto:f98c252f@in.mailhardener.com,mailto:s2a2b9xdf8@rua.powerdmarc.com;policy: quarantine - DKIM
-
Show 4 DKIM selectors
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDb6aMX8GCfz0/bSmcurFPaXhmgHLWH6AWpGd6z7bLgQzK4HQ3ZmTGcZWVbne6YhkC3HGHU0GMCpX0lydYBO2… - google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAn6UPLof/R0PU3pvuO+jh635dqXeD2HHfwcoQvsS6f7iBy4XesYhm5xlx1DKeI85J1vQeXejCM0xXEw… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzOzUTk+mxU6ZD7yC/6e7cOW/4kkiAZYGcdNm1Hwv5dDNKF9VHObckKJtwcIUvkL4qmGtCSn+1H66NTIUPA… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5HXVfsOmBlszLV24/kLkg2cf7ZpPZlnXjBDGqHW/diP8CxxLPZQm0Mn9oHaTXJHQIp7ExWjMlK0AUrJn0UtQ3Qd…
selectors probed - default:
Certificate (current)
WE1
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=*,autoplay=*,clipboard-write=*,encrypted-media=*,fullscreen=*,geolocation=(self),gyroscope=*,picture-in-picture=*,web-share=(self),payment=("https://act.mercyforanimals.org" "https://donate.mercyforanimals.org")- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests;default-src 'self';script-src 'self' 'unsafe-inline' file-cdn.mercyforanimals.org file-stg.mercyforanimals.org mfa.cachefly.net mfacdn.cachefly.net common.mercyforanimals.org act.mercyforanimals.org act.escolhaveg.com.br assets.gospringboard.io doublethedonation.com tgbwidget.com js.dev.shift4.com cdnjs.cloudflare.com cdn.jsdelivr.net www.google.com www.gstatic.com code.jquery.com ajax.googleapis.com player.vimeo.com www.youtube.com www.youtube-nocookie.com youtube.com youtube-nocookie.com platform.twitter.com www.instagram.com public.tableau.com connect.facebook.net www.tiktok.com *.tiktokcdn-us.com *.ttwstatic.com go.mercyforanimals.org pi.pardot.com bat.bing.com snap.licdn.com static.hotjar.com script.hotjar.com static.ads-twitter.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com googleads.g.doubleclick.net www.googletagmanager.com www.google-analytics.com www.googleoptimize.com *.fundraiseup.com *.stripe.com m.s- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups