novocure.com
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2002-09-15
- Expires
- 2027-09-15 484 days left
- Updated
- 2024-04-25
- Name servers
-
- harlee.ns.cloudflare.com
- henry.ns.cloudflare.com
DNS records live
- NS
-
- harlee.ns.cloudflare.com
- henry.ns.cloudflare.com
- MX
-
- 10 us-smtp-inbound-1.mimecast.com
- 10 us-smtp-inbound-2.mimecast.com
- TXT
-
Show 18 TXT records
airtable-verification=91e5f5fe0c5863d34aa4a0860ee240dbdocusign=966ef033-f25c-4c77-ba3b-02cc073143fecursor-domain-verification-hrhp3t=lQeUbITopoDaFAvEpDu66p8cWsuccessfactors-site-verification=ZTIwZTg4NGMwZGNjYjIxYjE1MmViM2VkYzI4M2ZhNjk0NGZmZTcyYjk4NjZjYWFhNGM2MWIzMmFkMWUwY2Q2Nw==dropbox-domain-verification=dnyh9l0rpy72+1/l6Zz/LXkf8//Or4OO5tN1Uz6LmWb1CG0AgfCLcsGDj1zrMprArZiMLx6MzoITSII9Py1D6zIStcjSu9HyMw==MS=ms80271783openai-domain-verification=dv-hVsJLQkkWVumUkwTem30VSIZgoogle-site-verification=NFoVzxhmlZer864q1ox4xTgo-AXbs6IsL-mfbjhcQ9wdropbox-domain-verification=v7kycbqmp821miro-verification=3273d804c89ad339b42cc9d3b93c240dac8cba45_kpgdl2oprrm32qop4i6zr1j2cjtfdrysmartsheet-site-validation=znEDo6ZiVY8gCFzyEYr4Js9RRYXU-MLFgoogle-site-verification=FVso2lv5J5ig_livk6eDyuM6-xMAsxny2C-E0CZlilcapple-domain-verification=qJJyrUQKqKpuGM2Tastro-domain-verification=cmm29gxyb127101mdn8t7c2xuMS=ms89265969atlassian-domain-verification=9Ew89abzuaX3XMlDBB2JWTG1RBCSoCAdY/B7Wigxranq7m7WmedhScDFalk7AVzU
Email authentication strong
- SPF
-
v=spf1 mx ip4:209.143.73.156 ip4:70.42.227.151 ip4:70.42.227.152 ip4:20.1.128.197 ip4:20.10.24.226 ip4:20.96.12.43 ip4:20.1.130.13 ip4:148.59.100.16/28 ip4:148.59.101.16/28 include:_netblocks.mimecast.com include:spf.aristotle.com include:mailgun.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarcreports@novocure.compolicy: quarantine - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCZOo9zsk8mLwb8jF04rzZt3jcXQO25kOSPOS31pLjx2LaGGKnHajr1ZHae2oKk0GgFPqF1auhvSohEux0hfV… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzpdcVnoJ+B9MW/aBT42prCZcMKWhGLLkBczpumlA42hf/nRqiwwwZ7DtAhPcpg/YBqvCRbrYQveFytsQiz… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzQvZ9kNerGj+32evJN7ReU2jXcAkT+/gm0yS6X6SNVciCy/l7sC5wEVliOuak+FlPDUV4TMjesR7QNxiBl…
selectors probed - selector2:
Certificate (current)
R13
Expires in 73 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.trackingplan.com *.visualwebsiteoptimizer.com vercel.live;style-src 'self' 'unsafe-inline' *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com www.googletagmanager.com fonts.googleapis.com fonts.gstatic.com;style-src-elem 'self' 'unsafe-inline' www.googletagmanager.com fonts.googleapis.com d5phz18u4wuww.cloudfront.net *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' d5phz18u4wuww.cloudfront.net *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com pagead2.googlesyndication.com *.eu1.gigya.com matomo-pro.novocure-dev.com cdn.cookielaw.org *.adsrvr.org secure.adnxs.com bh.contextweb.com vercel.live vimeocdn.com www.googletagmanager.com tr.contextweb.com f.vimeocdn.com www.gstatic.com *.vimeo.com vimeo.com snap.licdn.com app-script.monsido.com blob:;script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' app.vwo.com assets.novocure.biz googleads.g.doubleclick.net ct.pinterest.com s.pinimg.com *.visualwebs- strict-transport-security
max-age=31536000; includeSubDomains