myfcsfinancial.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- cdn.jsdelivr.net×2
- js.adsrvr.org×1
- js.hsforms.net×1
- www.facebook.com×1
- www.google.com×1
- www.googletagmanager.com×1
Contact
- Phone
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2006-01-26
- Expires
- 2029-01-26 981 days left
- Updated
- 2024-01-24
- Name servers
-
- ns1.zoneedit.com
- ns14.zoneedit.com
- ns7.zoneedit.com
- ns8.zoneedit.com
DNS records live
- NS
-
- ns1.zoneedit.com
- ns14.zoneedit.com
- ns7.zoneedit.com
- ns8.zoneedit.com
- MX
-
- 0 mxa-007b0e01.gslb.pphosted.com
- 0 mxb-007b0e01.gslb.pphosted.com
- TXT
-
Show 9 TXT records
logmein-verification-code=a9b42ee2-9278-4ff9-8917-ccb4eccf5c4f_9e7m28ptyuh8ztg86s0set3gq8rnos8_8l002hb3bc0ktlx7ik6d0gkex4o7nm9have-i-been-pwned-verification=944e8b9a89f0b52cb57659de9ecd16adMS=CFB0097EC7376BC8FE87057806E8E94D703BB486cloudflare_dashboard_sso=6c356635b83036970b2792265eae35afE46y10Do1B+z/EGc59aToNPBGEkLuRg6rZ9pIa2xpFhcKBUF/RbA5n1lNqmmAcIJlluIlcGi/01Gat4kbagmNg==_hei1tv8lzooafsx82beo181vxuwzzp036d9p4zzk3m8f0yk73rb5vvyrps2yqk4
- Verified for
-
- Atlassian
- DocuSign
- Dropbox
- Meta
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;policy: reject (enforced) - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAn99F/gg2ucQJUKoR3nmFLHoC2v1oVsUdXBIlMW4UngPQyUT7k/AxGo1zCWH8gzf/u3gTb9AcIyIHJs… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0++QJTxzIxhzSta3mEk1fFDfG6MK787khSzdhwTYnbGyXTmj8hBMsmNDjp0e95W+KUvyOmAZVrEcQv… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuJFBkNi7CoGOQhJlH7Nmyn7u9I7dZhNfcsmArzZNfZFLE6KYK24BUlPeCBO3MT9FgSshvd1X1pMqrgXPSu… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5P/N/GoBiF27QmjwqqJIMqxnaNF1UiRP9ZOAbB2CHi3j361WhKt2lpwAsl1MUAvxhjefH8FyW1Y8j1zWzS… - smtpapi:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76yoj…
selectors probed - selector1:
Certificate (current)
DigiCert EV RSA CA G2
Expired 14 days ago
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
browsing-topics=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; upgrade-insecure-requests; block-all-mixed-content; script-src 'self' 'nonce-OGdab8FOHk+xd/uwCirzJA==' 'strict-dynamic' https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://js.hsforms.net https://js.hs-scripts.com https://static.hsappstatic.net https://js.hubspot.com https://js.hs-banner.com https://js.hsadspixel.net https://connect.facebook.net https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://hello.myfonts.net; font-src 'self' https: data:; img-src 'self' https: data: blob:; connect-src 'self' https:; frame-src 'self' https://www.googletagmanager.com https://*.hsforms.com https://*.hubspot.com https://www.google.com https://insight.adsrvr.org https://match.adsrvr.org https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://indd.adobe.com; form-action *;- strict-transport-security
max-age=31536000; includeSubDomains