nva.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- images.ctfassets.net×14
- www.googletagmanager.com×2
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2000-03-07
- Expires
- 2030-03-07 1388 days left
- Updated
- 2025-02-13
- Name servers
-
- carl.ns.cloudflare.com
- olga.ns.cloudflare.com
DNS records live
- NS
-
- carl.ns.cloudflare.com
- olga.ns.cloudflare.com
- MX
-
- 5 nva-com.mail.protection.outlook.com
- TXT
-
Show 27 TXT records
apple-domain-verification=Fwt30EPmOstdpqV2Foxit-domain-verification=30211b9cbf72d7ac801cd43dc5a8e422MS=71B8C88D2CFAD342E365EDB821AFDB926244882Fatlassian-domain-verification=n90Sya3AX1tQ3O8IxKEgsr3lkXSLdtaeQbWaOsAueiCBr/8UMo/ozWTwOTYdDOccteamviewer-sso-verification=8157bee96c8344769c1d9ed456662533google-site-verification=RXPaHI5lnDWqkLiyBqIGNQO5PdH_fZc-X-lTvQ_EaCkMS=ms60192622ftgi7um1s8lssdkhk036ubour6amazonses:vVMnnTKSI/fZ+EKmJitVpUtQM0kOsTY+as5vMy8kZi4=52790238-f1e2-4cce-9962-0a930567380dn7zbebKG8lv+0YNZb4u5lHwqPfiYV6X+h4TzpWOj1qfTxuDKLKnmCnlKTcwzM60eXlMsBMeAOA685o4GQ2t/KA==5c4a494cd047a694697c0efdcb7796553994d6b6google-site-verification=G9cMGWRndn5DPYOX1pTS6CYIdLLPMwiRuD1Vt02kkzkcisco-ci-domain-verification=2d9ceeda2be0983b4fb567cd92fdfbaf8b65c543c894f7e2d25d0770a9ae0dc2smartsheet-site-validation=e_ytXYQRzv6FVksIIhScavXUGf2B7Bbsk99ts2c1p7cr89h3sbd5rhcg72google-gws-recovery-domain-verification=38896833duo_sso_verification=dlCbNAnrhvM20ehzVVwmPRwRhioTyyJM6T4G6Jb2tr59RtyXhzjOXmIfJWDPxBl067su6ud9mini8i472ora1jh12t_smpn56bnuy5kqur13pu1d86a1cmxca3dhcz4s7zjqym5qs45d3zt2bd8htxflyxdjk8pd74020776d00q099r2vkcsl532lbw=w1tlbCvyVNFEGhQm8MifAYg3GMA8Q0Bw8jcvrOshupVI_1z52bax0tp0e6cwz40wao1kwg83x6pjasv=74eea85633c6b872b38410670eb3f3a0v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email mx include:spf.protection.outlook.com ip4:209.143.155.182 ip4:208.185.229.45 a:b.spf.service-now.com include:mailgun.org ~allgoogle-site-verification=F46t0xx1XIoHmy5GtxwKjIaR_JASdzhyvDj-FuzuQ6s
Certificate (current)
WE1
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://videos.ctfassets.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://cdn.amplitude.com s3.amazonaws.com www.gstatic.com widgets.jotform.io nva.jotform.com code.jquery.com *.azureedge.net googleads.g.doubleclick.net *.google-analytics.com *.weglot.com *.googletagmanager.com www.youtube.com *.erexpress.com lifelearn-cliented.com connect.televet.com timely.com events.timely.fun *.rvetlink.com connect.facebook.net www.facebook.com tracking.callmeasurement.com nva.vetstoria.com ajax.googleapis.com maps.googleapis.com www.google.com *.quiz-maker.com *.audioeye.com; img-src 'self' * https: data:; style-src 'self' 'unsafe-inline' cdn-images.mailchimp.com nva.jotform.com *.weglot.com fonts.googleapis.com *.poll-maker.com *.quiz-maker.com *.audioeye.com; font-src 'self' data: cdn.jotfor.ms fonts.googleapis.com assets.contentstack.io fonts.gstatic.com google.com *.audioeye.com; base-uri 'self'; form-action 'self' mailchimp.com nva.jotform.com; connect-src- strict-transport-security
max-age=63072000; includeSubDomains; preload