museumofthebible.org
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (9)
- images.prismic.io×9
- cdnjs.cloudflare.com×4
- code.jquery.com×1
- fonts.googleapis.com×1
- static.addtoany.com×1
- static.cdn.prismic.io×1
- unpkg.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Address
- St. SWWashington, DC 20024
DNS records live
- NS
-
- ns-1478.awsdns-56.org
- ns-1704.awsdns-21.co.uk
- ns-487.awsdns-60.com
- ns-834.awsdns-40.net
- TXT
-
Show 6 TXT records
3jtcs4jd3w5nmj00dmjlxlksp4kncv8t_h23w7xidne2bvvxfxpkftcck53grmcr_so9szgxtk9gp5zq2a04dq2ouykctk8cjecgf7s06u1rhoe38ekeeddcsups2j69rjceb6nk99d3gr7j4fra3g24fn0km06iq6bh379duv7vtq
- Verified for
-
- Apple
- GlobalSign
- Meta
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo/ecgjmjpSppIrXHD2yNz2XGKkld/NwfTgrf75YHK0Du/cKjY2c+k+dSb4NihqbxA+FCIH7EFjBDAn7D4i… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJjD0aDGVQWJWRUDYK5Wqr+5WmZu+V4qUdABqcHs7g05D41MgT8YVhSqH8oTIEyKpTuV29T+/7zbCqBmqgvzOTPg…
selectors probed - s1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 125 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'unsafe-inline' 'unsafe-eval' museumofthebible.org museumofthebible.cdn.prismic.io info.museumofthebible.org login.museumofthebible.org www.museumofthebible.org phpstack-448274-1403762.cloudwaysapps.com player.vimeo.com api.vimeo.com vimeo.com www.youtube.com museumofthebible.prismic.io www.googletagmanager.com www.google-analytics.com analytics.google.com adservice.google.com 8092262.fls.doubleclick.net stats.g.doubleclick.net static.doubleclick.net td.doubleclick.net googleads.g.doubleclick.net bid.g.doubleclick.net prismic.io wroom.io code.jquery.com googleapis.com ajax.googleapis.com recruitingbypaycor.com www.google.com cdnjs.cloudflare.com static.cdn.prismic.io apps.idonate.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com cs.yieldoptimizer.com tag.yieldoptimizer.com pixel.mathtag.com 11007.iceuc.com iceim01.iceuc.com s7.addthis.com m.addthis.com www.cognitoforms.com static.cognitoforms.com api.idonate.com embed.idonate.com widget.spreaker.com a36748.act- strict-transport-security
max-age=31536000;