midas.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Ghost
- Analytics
-
- Google Analytics
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (9)
- www.googletagmanager.com×3
- edge.fullstory.com×2
- rw.marchex.io×2
- ssl.google-analytics.com×2
- www.google-analytics.com×2
- cdn.cookielaw.org×1
- cdn.optimizely.com×1
- challenges.cloudflare.com×1
- js.web-2-tel.com×1
Social
Registration
- Registrar
- GoDaddy Corporate Domains, LLC
- Created
- 1997-01-06
- Expires
- 2030-01-05 1326 days left
- Updated
- 2025-10-28
- Name servers
-
- chase.ns.cloudflare.com
- savanna.ns.cloudflare.com
DNS records live
- NS
-
- chase.ns.cloudflare.com
- savanna.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 17 TXT records
facebook-domain-verification=51q8jro8y8q0v07fhn7vj2b5sofwu285vr759crfoqgccjms7b35035czoho-verification=zb01152781.zmverify.zoho.comhqfri7gsc9h8q81uj35b9eutmd62qnughdcscnjk3per97vt9luhaafp9aa5so6ijkgfbm7ous6si3u28i3c67ep6fi622fgfvbogbhqgoogle-site-verification=ufJIsxwCmLoSvQw7U_juSs4oo62joJStROF4ZLxP2Zgmiro-verification=b1c0fea04967fd028aea3464e656f6702b03133dgoogle-site-verification=aCaX1Az6xEqFwUrDOldLfTCrjWx4W1zzKJlU3lEipSgapple-domain-verification=D8fCiUbDM7getRGmtv1ITnWPbvHVLXo-9ELe5UXc8cExdfT3Hrfcisco-ci-domain-verification=1afcb420b39ba0e185836d71c44d20ff305532affb3c6fe724f65be8c6d87a7cisco-ci-domain-verification=2b9499e44ca7cd55f7c681e20f2e522849981e165ac7a52a4fe512bd94f3539fMS=ms953404126vdn3qdj9liv3m4p5upuh1dqtkrovag_verification_token=353FCEEFACAF412DBE2768DF8CE021BD
Email authentication partial
- SPF
-
v=spf1 ip4:192.55.104.85 ip4:192.55.104.84 ip4:192.55.104.74 ip4:192.55.104.72 ip4:66.159.100.22 ip4:129.80.174.121 ip4:63.250.236.124 ip4:38.75.129.124 ip4:68.64.46.200 include:spf-00001401.pphosted.com include:spf-00ad5201.pphosted.com include:_spf.google.com include:_spf.qualtrics.com include:u55903414.wl165.sendgrid.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; fo=1; rua=mailto:uft3jobr@ag.us.dmarcian.com; ruf=mailto:uft3jobr@fr.us.dmarcian.com;policy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmhFscahYybkXO8EJN9VM63c6DkSpmorDrbbf3OiqvjOtL4Bu+VU1fZ14tSSCm25/HiP+bOUfAWYIqW… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyJw73y23AkG20AYMMpxG3iC9yb35xAt9hazPGR7/qFJNXF1k8kP4hJCYE1t7Uf7zaV12WmtrrZDckt… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqJQIkuGcCZ26Gea2RnFmav5Tineu0ZbbixC4obhKcSwqchk7S7NtbGVYiiZG467fhdTosI97sCjvXofdgK… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5orNaxNNiXfh5zHzFqr3czZMkOeLD0P9vW3Os+As8TJ7cZPaIfbDjUD/mitpLq5tF3tujijpViu2600VI+…
selectors probed - google:
Certificate (current)
WR3
Expires in 63 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-src 'self' *.facebook.com *.owneriq.net *.marchex.io *.doubleclick.net *.googletagmanager.com *.youtube.com *.midas.com *.bazaarvoice.com *.comenity.net *.google.com *.jotform.com *.jotform.io *.stripe.com *.tealiumiq.com ct.pinterest.com *.optimizely.com *.adsrvr.org *.cloudflare.com m.me *.rfihub.com *.qualtrics.com *.web-2-tel.com device.uat.proveapis.com device.proveapis.com auth.svcs.verizon.com intent:; frame-ancestors 'self' *.facebook.com *.owneriq.net *.marchex.io *.doubleclick.net *.googletagmanager.com *.youtube.com *.midas.com *.bazaarvoice.com *.comenity.net *.google.com *.jotform.com *.jotform.io *.stripe.com *.tealiumiq.com ct.pinterest.com *.optimizely.com *.adsrvr.org *.cloudflare.com m.me *.rfihub.com *.qualtrics.com *.web-2-tel.com device.uat.proveapis.com device.proveapis.com auth.svcs.verizon.com intent:- strict-transport-security
max-age=63072000; includeSubDomains; preload