netaffinity.io
HTML metadata
Technology
- Server
- Apache
Third-party hosts loaded (1)
- kit.fontawesome.com×1
DNS records live
- NS
-
- ns-1391.awsdns-45.org
- ns-1582.awsdns-05.co.uk
- ns-286.awsdns-35.com
- ns-968.awsdns-57.net
- MX
-
- 10 mail.hotels.netaffinity.net
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 mx include:netaffinity.net -allstrict (-all) - DMARC
-
v=DMARC1;p=none;sp=none;pct=100;rua=mailto:spamadmin@netaffinity.io;ruf=mailto:spamadmin@netaffinity.iopolicy: none (monitoring only) · sp=none - DKIM
-
- default:
v=DKIM1; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC2rZjQXw6TMWGcwabmdS3eBvqzYdiTRJG5xqqOyI6z0L4LhYrUo681XUu9kQCZDQQ6yym9YfJbIXbU35WTVxsG…
selectors probed - default:
Certificate (current)
R13
Expires in 32 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
frame-src 'self' 'unsafe-inline' 'unsafe-eval' * blob: data: * ; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: app.netaffinity.io app.office.netaffinity.net app.demo.netaffinity.net app.uat.netaffinity.net *.ecodev.netaffinity.net *.staging.ecodev.netaffinity.net *.host.staging.ecodev.netaffinity.net *.adyen.com bat.bing.com maxcdn.bootstrapcdn.com checkoutshopper-test.adyen.com checkoutshopper-live.adyen.com cdnjs.cloudflare.com cdn-a.cumul.io app.cumul.io pay.sandbox.datatrans.com pay.datatrans.com www.facebook.com connect.facebook.net forms.hsforms.com heapanalytics.com cdn.heapanalytics.com js.hsforms.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js-eu1.hs-scripts.com js.hsleadflows.net js-eu1.hs-analytics.net js-eu1.hscollectedforms.net forms-eu1.hscollectedforms.net forms-eu1.hsforms.com js-eu1.hs-banner.com api.hubspot.com api-eu1.hubspot.com app.hubspot.com track.hubspot.com track-eu1.hubspot.com forms.hubspot.com js.hubspotfeedback.com pay.google.co- strict-transport-security
max-age=31536000; includeSubDomains; preload;