naeci.com

.com crawl

First seen 2026-05-31 · Last seen 2026-06-01 · ok HTTP/1.1 200 2490 ms crawled 2026-06-01

US · 169.48.37.93 · AS36351 IBM Cloud

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
North Arkansas Electric Cooperative
Language
en-CA

Technology

Server
Apache
jQuery
3.3.1 known XSS (<3.5)
Stack
PHP
Analytics
  • Google Tag Manager

Third-party hosts loaded (6)

  • cdnjs.cloudflare.com×8
  • cdn.jsdelivr.net×4
  • stackpath.bootstrapcdn.com×2
  • code.jquery.com×1
  • www.google.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone

Registration

Registrar
GoDaddy.com, LLC
Created
1996-05-01
Expires
2027-05-02 334 days left
Updated
2022-10-15
Name servers
  • ns1.ecark.org
  • ns2.ecark.org

DNS records live

NS
  • ns0.dnsmadeeasy.com
  • ns1.dnsmadeeasy.com
  • ns2.dnsmadeeasy.com
  • ns3.dnsmadeeasy.com
  • ns4.dnsmadeeasy.com
MX
  • 100 mx1-us1.ppe-hosted.com
  • 100 mx2-us1.ppe-hosted.com
TXT
Show 5 TXT records
  • _px5jy7cjz64rmn0ttpqn4ufrp1xh6uf
  • ppe-486c51f6e2f4b9856db5dc68bc3eb66caef87368
  • TdexdtbGBcOfzWaRGgk9Kj94z7/KMTZhHXgFupAFW/bsSdX+JKiELU76pNRRZbgRoQMO3kPsFfTdCp1AGjRXPA==
  • amazon-business-verification=47d7541262f1a8060dce477b207e65b6d4dc522f56423a3520e8babfd268b224
  • _d1xo9kbopa6dtozasy8awqx5v9mjzev
Verified for
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:_spf-us.ppe-hosted.com include:siraza.net ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; pct=100;
policy: quarantine
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsbghGoRxxj2DIC+FiPQ46RUfWb8ENsZmKqsoffq5H6l0KO3kkxCCDSoaMfW01LTV5V2vzpmwXABLHm2RTB…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwMIj2cKVyhlIw08rp1C+2rqMECbAFCd0PDjvPOaDPy0qb45Fxlc8VukkPYu7yP8HJ+RcAdjEnljldpmWUF…
selectors probed

Certificate (current)

R13
from 2026-05-04 to 2026-08-02
Expires in 62 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://www.naeci.com/

present
  • x-frame-options
findings
  • missing HSTS
  • missing Content Security Policy
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN

Links to (5)

Linked from (1)