myunishippers.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- Fonts
-
- Adobe Fonts
- Google Fonts
Third-party hosts loaded (5)
- cdn.sheetjs.com×1
- fonts.gstatic.com×1
- service.force.com×1
- use.typekit.net×1
- whatfix.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2019-10-31
- Expires
- 2026-10-31 164 days left
- Updated
- 2026-03-10
- Name servers
-
- alberto.ns.cloudflare.com
- maisie.ns.cloudflare.com
DNS records live
- NS
-
- alberto.ns.cloudflare.com
- maisie.ns.cloudflare.com
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 247 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
'sameorigin' https://*.datadoghq.com- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.myunishippers.com https://myunishippers.com https://www.myunishippers.com https://*.launchdarkly.com; frame-src 'self' blob: *.myunishippers.com https://myunishippers.com https://service.force.com https://auth.unishippers.com https://whatfix.com https://*.whatfix.com https://transaction.hostedpayments.com *.quicksight.aws.amazon.com https://*.launchdarkly.com; img-src 'self' *.myunishippers.com https://myunishippers.com https://www.myunishippers.com https://wwex.com https://*.launchdarkly.com data: https://www.google-analytics.com https://*.gravatar.com https://*.launchdarkly.com; script-src 'self' *.myunishippers.com https://myunishippers.com https://www.myunishippers.com 'unsafe-inline' *.force.com *.salesforceliveagent.com https://*.whatfix.com https://whatfix.com https://www.google-analytics.com https://code.jquery.com https://wwex.com https://d758cqe2bs24d.cloudfront.net *.quicksight.aws.a2z.com blob: https://*.launchdarkly.com; style-src 'self' 'unsafe-inlin- strict-transport-security
max-age=31536000; includeSubdomains; preload