morshed-bdc.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Nuxt
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (2)
- gateway.esite-lab.com×9
- static.cloudflareinsights.com×1
Social
Contact
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2020-11-01
- Expires
- 2026-11-01 164 days left
- Updated
- 2025-01-23
- Name servers
-
- macy.ns.cloudflare.com
- wesley.ns.cloudflare.com
DNS records live
- NS
-
- macy.ns.cloudflare.com
- wesley.ns.cloudflare.com
- MX
-
- 10 mx1-hosting.jellyfish.systems
- 20 mx2-hosting.jellyfish.systems
- 30 mx3-hosting.jellyfish.systems
- TXT
-
linkedin-site-verification=ed48cbc6-d219-4e8f-aff4-a1f5cad79bbd
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 +mx +a +ip4:198.54.116.43 +include:spf.web-hosting.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4FtaJLbFkLixqBnTTU0LRm5oldwrEVr573o5H1V8Sm7fmiP0lofWFELwthIczlPGD1/Bfrw4y+gZ42…
selectors probed - default:
Certificate (current)
WE1
Expires in 21 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; font-src 'self' https: data:; form-action 'self'; frame-ancestors 'self'; img-src 'self' data: https://gateway.esite-lab.com https://cdn.example.com; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; script-src 'self' https: 'unsafe-inline' 'strict-dynamic' 'sha256-p0oL/gcBD9mlRymPpIYvLk7vtPR3xma4dpOxcS3B0vk=' 'sha256-87YeLM6S5yA8GyoE73qm2rFzYC1SqCQ1p0/F2M/2tqA=' 'sha256-coaE/TsgpnMsU1J1MdQzXCu+qG1yxdqrmqGkriXz/9Q=' 'sha256-wlZpN52fzmwfXTl5xRfJqsCqY+RNGAtB/d3Z+un/VYM=' 'sha384-LgvTCCatkW0zV0GDiC2U6FbHzQFlcQq3YUwhpdMC59uaFpDmXTbUHeFl65OwzPPh' 'sha384-YDttcixedZAfll1+JuiL6euVshoTS7uLg8+zFwxdhqT8VcOhRPlY/kZTymjXibAz' 'sha384-r9LJ1IJOW7TKhtiA749EV0TgrPYJIgeSkAjxfugfSjm2Qvxn9dW7RQUmN6nEv2Rb' 'sha384-koWQi39lzAfwATSm9LH+p3d/iZEXG1iNQ6BQoihK6j+lUEaHhcK4m33TdkKOTerM' 'sha384-tp0sLW/T8vzvCWj0xxnh4xU3GO0hfkrH+1ZHgbQQdieYViuNRt863z9gEBAVUtMc' 'sha384-xLjdb7Pgw4JDYTkJCz1Ge31UVlSBSpalsB4/Bg1xQHQy/STwDelua5yVJWlSOKy6' 'sha384-pNBN7cmKnmBZAupBLz3mmfZ- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
credentialless- cross-origin-resource-policy
same-origin