mymassanutten.com
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Drupal
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2026-02-04
- Expires
- 2031-02-04 1722 days left
- Updated
- 2026-03-13
- Name servers
-
- pdns03.domaincontrol.com
- pdns04.domaincontrol.com
DNS records live
- NS
-
- pdns03.domaincontrol.com
- pdns04.domaincontrol.com
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 115 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://fonts.googleapis.com https://salesiq.zoho.com https://js.zohocdn.com https://js.zohostatic.com https://static.zohocdn.com https://www.googletagmanager.com https://www.google-analytics.com https://customerbot-app-dchge3amfee3fwey.eastus-01.azurewebsites.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://css.zohocdn.com https://css.zohostatic.com https://static.zohocdn.com; img-src 'self' data: blob: https:; font-src 'self' https://fonts.gstatic.com https://css.zohocdn.com https://css.zohostatic.com https://static.zohocdn.com data:; media-src 'self' blob: https://static.zohocdn.com; connect-src 'self' http://localhost:7071 https://*.massresort.com https://fonts.googleapis.com https://api.weather.gov https://*.weatherstem.com https://data.weatherstem.com https://maps.googleapis.com https://maps.gstatic.com https://salesiq.zoho.com https://salesiq.zohopublic.com https://vts.zohopublic.com ht- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none