onited.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- fonts.googleapis.com×2
- cxppusa1formui01cdnsa01-endpoint.azureedge.net×1
- fonts.gstatic.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- CSL Computer Service Langenbach GmbH d/b/a joker.com
- Created
- 2022-02-21
- Expires
- 2028-02-21 640 days left
- Updated
- 2026-02-04
- Name servers
-
- aida.ns.cloudflare.com
- piotr.ns.cloudflare.com
DNS records live
- NS
-
- aida.ns.cloudflare.com
- piotr.ns.cloudflare.com
- MX
-
- 0 onited-com.e-v1.mx.microsoft
- TXT
-
_acme-challenge.join-onited.com TXT EQIPN6IuBJtmhGXugDSr5ARqU9TrocTrZzK9Hy7rFAg_acme-challenge.join-onited.com TXT ogKLaCHpw1sj2Xh-Svzxx0SPeWY4eRqR2AG5OJwPPshpe-greenlake-domain-verification=7539395654476d667273444a61417767656d4a442d795a47644730725468626f
- Verified for
-
- DocuSign
- Dynamics 365
- OpenAI
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.eu.exclaimer.net include:autotask.net include:catsoneemail.com include:spf.afas.online -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; adkim=r; aspf=r; pct=100; ri=86400; ruf=mailto:reports.internalit@onited.com; rua=mailto:8df9876b8a5d4c85b55ca18a2ea18ecf@dmarc-reports.cloudflare.net,mailto:reports.internalit@onited.compolicy: reject (enforced) · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqf2nRx95lm3OxYIEqhJ4kxqMuVEOtdTRzurCAtO2OviW7dXcKq7RDYMg5ucDwmSa1a3Xq+6bBjBsOI… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0YvZBHQb9KL9yA3/+vEuadUIcMry8B0hFrlev6kIAkm1u2YgIB7dEM8cSetBrgjcWa7Kg7LtBdD3Vh…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 63 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' * data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' * https: http: data:; style-src 'self' 'unsafe-inline' * https: http: data:; img-src * data: blob:; font-src * data:; connect-src * wss: ws:; media-src * data: blob:; object-src *; child-src *; frame-src *; worker-src * blob:; manifest-src *;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none