montran.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- fonts.googleapis.com×4
- js.hs-scripts.com×2
- assets.calendly.com×1
- fonts.gstatic.com×1
- gmpg.org×1
- www.google.com×1
Social
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 1995-10-12
- Expires
- 2034-10-11 3067 days left
- Updated
- 2025-03-21
- Name servers
-
- ns-1295.awsdns-33.org
- ns-1702.awsdns-20.co.uk
DNS records live
- NS
-
- ns-1295.awsdns-33.org
- ns-1702.awsdns-20.co.uk
- ns-224.awsdns-28.com
- ns-738.awsdns-28.net
- MX
-
- 10 zimbra.montran.com
- 20 mail.montran.com
- TXT
-
Show 7 TXT records
jetbrains-domain-verification=3z1s2zrp8bpbapfi6gnnv6bxxopenai-domain-verification=dv-wiE7x7aB4BAYG8q8eiM7A4gtMS=ms24375597atlassian-domain-verification=WutJNDSXI95sa4KloPO8aGwS1RA5qZpdoFdh84iYqDu9hOuwFl9j9DmU0nGLNAjicisco-ci-domain-verification=50fde17e1e4949cbfb43a9380ec7b16b6922a128cd445e0d0be75510cd1ab060google-site-verification=Lp0U3-Rpe6pvGManFQ6-jD7zPfHAv2viBClzAO6EUp8google-site-verification=tFWCJCl4UCJbk1LSRn7WwJlQvcouDtrmcSIJW9FJNWc
Email authentication strong
- SPF
-
v=spf1 a:zimbra.montran.com a:mail.montran.com ip4:86.122.14.72/29 ip4:50.248.188.244/32 ip4:128.177.77.75/32 ip4:109.166.216.170/32 ip4:109.166.216.166/32 ip4:5.2.199.163/32 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:admin@montran.com;policy: quarantine - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA62Gm+sCwff66hKnsv2Z3F+CIhGbGLP5C99/boXY3SbqV8L6+T/fi3iD+usSIW4qpL0cRjtbnAs3sVNopbW… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsIO03JayXVHRG/zAfgMHJEZz/zHbdy5x00csKntCrFG2Ha385CQAIIMVdVW2GGKpCL3PMtfq5GFUNeLFpj…
selectors probed - s1:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 164 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), midi=(),sync-xhr=(),accelerometer=(), gyroscope=(), magnetometer=(), camera=(), fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' http: https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https: data:; style-src 'self' 'unsafe-inline'; font-src 'self' https:, default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'- strict-transport-security
max-age=31536000- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none; report-to='default'- cross-origin-resource-policy
cross-origin