nar.org

.org crawl

First seen 2026-04-18 · Last seen 2026-05-16 · ok HTTP/1.1 200 2863 ms crawled 2026-05-13

US · 52.87.105.192 · AS14618 Amazon.com, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Home - National Association of Rocketry
Description
The National Association of Rocketry (NAR) is an organization dedicated to consumer safety, youth education, and the advancement of technology in the hobby of spacemodeling (sport rocketry).
Language
en

Technology

Analytics
  • Google Tag Manager

Third-party hosts loaded (4)

  • images.clubexpress.com×6
  • www.googletagmanager.com×3
  • s3.us-east-1.amazonaws.com×1
  • static.addtoany.com×1

Social

Contact

Email

Registration

Registrar
Domain.com - Network Solutions, LLC
Created
1992-03-25
Expires
2027-03-26 311 days left
Updated
2026-03-11
Name servers
  • ns1.blastzonewebhosting.com
  • ns2.blastzonewebhosting.com

DNS records live

NS
  • ns1.blastzonewebhosting.com
  • ns2.blastzonewebhosting.com
MX
  • 10 nar.org.c2.mx1.ik2.com
  • 20 nar.org.c2.mx2.ik2.io
  • 30 nar.org.c2.mx3.ik2.eu
TXT
  • google-site-verification=M4uCT8R1r_FrVw74IEdWj7ts77SqdikkLyv-Mvgmjc8

Email authentication partial

SPF
v=spf1 mx a ip4:216.215.30.32/28 a:mailer.clubexpress.com include:clubexpress.com include:amazonses.com include:mxroute.com include:smtp2go.net -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:dmarc@nar.org; ruf=mailto:dmarc@nar.org; fo=0:1
policy: none (monitoring only)
DKIM
  • default: v=DKIM1; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQeXuNZaPAUQTuG0dys4xmWPLwUBND1wV6FGOz8KWLjLwXRtyMycnGWUBi/bryTBjydJbH7d1V9hi1CXnG3rKT…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA DV R36
from 2026-04-06 to 2026-10-22
Expires in 156 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://nar.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https: *; script-src https: 'unsafe-inline' 'unsafe-eval' *;img-src data: https:;font-src data: https:;style-src https: 'unsafe-inline' *;upgrade-insecure-requests;frame-ancestors 'self'; base-uri 'none'; frame-src mailto: *; worker-src blob: * ; child-src blob: ;
strict-transport-security
max-age=31536000; includeSubDomains; preload, max-age=31536000

Links to (8)

Linked from (2)