newtek.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (5)
- www.vizrt.com×6
- stats.wp.com×2
- fonts.googleapis.com×1
- maxcdn.bootstrapcdn.com×1
- player.vimeo.com×1
Social
Contact
- Phone
Registration
- Registrar
- Abion AB
- Created
- 1993-12-04
- Expires
- 2026-12-03 198 days left
- Updated
- 2025-11-26
- Name servers
-
- a.portsdns.se
- b.portsdns.net
DNS records live
- NS
-
- a.portsdns.se
- b.portsdns.net
- MX
-
- 10 newtek-com.mail.protection.outlook.com
- TXT
-
Show 13 TXT records
MS=ms35533348MS=8F5B66E59B1028D2097A02A1828D0F09893FDD9C7c01fikg242r06n0qns6ud76s5v=DMARC1starfield-verification=glr6r2j0ci3mnc21mhq6tius6ssmartsheet-site-validation=SaxVw_FGSFYvn33AmyBW4-UzsC3ccw75pardot428312=32a50c007ae0f445387e03d5e02c3f64c7afe6ece6a7c2469299d48db8bb746bms-domain-verification=55146d59-b986-43f6-b070-f3e90e1547dalucid-verification=mht8dmf*RZN7akc@cwagoogle-site-verification=U1GD_4I9qz_xbAar8R3QZ_mg6_b6M6oaU9c-nSpdBwsdetectify-verification=d9eeb1f06483fe49308fac2de37ae231bw=H6nee0chZ4uQZPdBYNIKWsboxyz9jDPR1nYFsFlnhjWKadobe-idp-site-verification=b3cc0e860ee67a9ec85b3290cb735601224f53188da869defa6b3887a2fa29c1
Email authentication weak
- SPF
-
v=spf1 mx a:mx1.vizrt.com a:mx2.vizrt.com include:spf.protection.outlook.com include:mktomail.com include:aspmx.pardot.com include:mail.zendesk.com include:_spf.salesforce.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCyCILxhF0f0p1SqCUBORYgeIujDppfkieIoVW6HdNVWdVffLeV77iLf+snuVobSG3/rU5v8boWipvQObA1Ll… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArRdb19+plJ/VykrB6pnoq/jz81QzSOv1HywezMneEm3ultgoE7V7EIwZx34cQi2xP6f2yAG+xIuHwc…
selectors probed - selector1:
Certificate (current)
E8
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), display-capture=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(self), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), usb=(), xr-spatial-tracking=(), gamepad=(), serial=()- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; block-all-mixed-content; object-src 'none'; connect-src 'self' https://cms.vizrt.com https://www.vizrt.com https://cdn.plyr.io https://bat.bing.com https://b.clarity.ms https://px.ads.linkedin.com https://pagead2.googlesyndication.com https://www.facebook.com https://ad.doubleclick.net https://www.google-analytics.com https://www.google.com https://transactional-api.hu-manity.co https://designer-api.hu-manity.co/ https://maps.googleapis.com https://vimeo.com; style-src 'unsafe-inline' 'self' https://cms.vizrt.com https://www.vizrt.com https://p.typekit.net https://use.typekit.net https://fonts.googleapis.com https://s0.wp.com; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://cms.vizrt.com https://www.vizrt.com https://cdn.plyr.io https://*.cloudfront.net https://*.workable.com https://www.gstatic.com https://go.vizrt.com https://js.driftt.com https://static.ads-twitter.com https://pi.pardot.com https://secure.jaup0lake.com/js/216941.js https://www.clar- strict-transport-security
max-age=31536000;includeSubdomains
Links to (6)
- facebook.com×2
- instagram.com×2
- linkedin.com×2
- twitter.com×2
- vizrt.com×2
- youtube.com×2