michigannewssource.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Google AdSense
- Meta Pixel
- Fonts
-
- Google Fonts
- Social widgets
-
- Twitter Widget
- Vimeo Embed
Third-party hosts loaded (30)
- cdnjs.cloudflare.com×10
- www.googletagmanager.com×3
- connect.facebook.net×2
- platform.twitter.com×2
- a.vimeocdn.com×1
- api.twitter.com×1
- b.vimeocdn.com×1
- clients6.google.com×1
- cloudflare.com×1
- edge.quantserve.com×1
- facebook.com×1
- fonts.googleapis.com×1
- google-analytics.com×1
- google.com×1
- googletagservices.com×1
- graph.facebook.com×1
- img.youtube.com×1
- pagead2.googlesyndication.com×1
- pixel.quantserve.com×1
- player.vimeo.com×1
- plus.google.com×1
- quantcast.com×1
- quantserve.com×1
- secure-a.vimeocdn.com×1
- secure-b.vimeocdn.com×1
- secure.quantserve.com×1
- twitter.com×1
- urls.api.twitter.com×1
- vimeo.com×1
- vimeocdn.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2022-02-04
- Expires
- 2027-02-04 261 days left
- Updated
- 2026-02-05
- Name servers
-
- ns17.domaincontrol.com
- ns18.domaincontrol.com
DNS records live
- NS
-
- ns17.domaincontrol.com
- ns18.domaincontrol.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=Q65YMb61IH3FDkCQSogNM-kZ8e6BEOUjTAqNL8rwcpkgoogle-site-verification=rAzJ2nv0ZxcetJRtYkfBWspCCp2w4Cj86hUXwz662_A
Email authentication partial
- SPF
-
v=spf1 +ip4:69.16.249.30 +include:dc-aa8e722993._spfm.michigannewssource.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAz2D9peYOHllkbK9QQdHVvQzhXaOXeK1c59IoydAuyvXieGkkBiSKN74QHhe+SnKd13lhr+MeECrUhA… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - default:
Certificate (current)
R13
Expires in 56 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
upgrade-insecure-requests; default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob:; style-src data: 'unsafe-inline' https:; img-src data: https: blob:; font-src data: https:; connect-src https: wss: blob:; media-src data: https: blob:; object-src https:; child-src https: data: blob:; form-action https:;- strict-transport-security
max-age=15768000; includeSubdomains; preload, max-age=300