nwoesc.org

.org crawl

First seen 2026-05-01 · Last seen 2026-05-15 · ok HTTP/1.1 200 3330 ms crawled 2026-05-08

US · 208.108.122.165 · AS62724 Northwest Ohio Computer Association

Reputation 100/100

Classifying

HTML metadata

Title
Northwest Ohio ESC
Language
en

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts
Third-party hosts loaded (8)
  • cdnjs.cloudflare.com×20
  • ajax.aspnetcdn.com×3
  • fonts.googleapis.com×2
  • nwoesc.gofmx.com×1
  • translate.google.com×1
  • www.eschoolview.com×1
  • www.googletagmanager.com×1
  • www.juicer.io×1

Social

Contact

Phone

Registration

Registrar
GoDaddy.com, LLC
Created
2009-11-30
Expires
2030-11-30 1655 days left
Updated
2026-01-14
Name servers
  • exdns2.nwoca.org
  • exdns1.nwoca.org

DNS records live

NS
  • exdns1.nwoca.org
  • exdns2.nwoca.org
MX
  • 10 smtp.google.com
TXT
Show 6 TXT records
  • MS=996359A844E855DECBEFEE1CA1307F25F9584B51
  • duo_sso_verification=jOeWNrYYpp7Q00lhcqOgJvMYQp9QcguYxcqtFW57Oj8athBYEmdORm5Ubp2M0cfZ
  • apple-domain-verification=4MtWdH2opYfxxWI7
  • cisco-ci-domain-verification=39c6d50638bf586a7d1be9ddf83ff2f60ec2bb55ee77114e911e255ea3afa491
  • IRN=124297
  • DAS=NWOCA

Email authentication strong

SPF
v=spf1 ip4:208.108.121.0/24 ip4:208.108.245.26 include:_spf.google.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@nwoesc.org
policy: quarantine · pct=25
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqHcr3+r71d7EpmWQvDHfCjWlzT97DQRvfueltzkxoVYAaSA3n4TSvLuz3PV7eCGH+JNOQ4Hsx5V1O1…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificates

Loading certificate

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.nwoesc.org/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Permissions Policy
Header values
referrer-policy
no-referrer, strict-origin-when-cross-origin
x-content-type-options
nosniff
content-security-policy
upgrade-insecure-requests; default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https:; media-src 'self' blob: https:; worker-src blob:; connect-src 'self' https:; img-src 'self' https: data:; style-src 'self' https: 'unsafe-inline'; base-uri 'self'; form-action 'self' *.eschoolview.com syndication.twitter.com platform.twitter.com accounts.google.com script.google.com *.paypal.com *.paypalobjects.com *.venmo.com; font-src 'self' https: data:; object-src 'none'; child-src https:; frame-src https:; frame-ancestors https:;
strict-transport-security
max-age=31536000; includeSubDomains; preload
cross-origin-opener-policy
same-origin-allow-popups

Links to (14)

Linked from (1)