openomb.org
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- cdnjs.cloudflare.com×1
- www.googletagmanager.com×1
Contact
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2024-04-30
- Expires
- 2027-04-30 345 days left
- Updated
- 2026-05-01
- Name servers
-
- ns-1172.awsdns-18.org
- ns-1903.awsdns-45.co.uk
- ns-407.awsdns-50.com
- ns-877.awsdns-45.net
DNS records live
- NS
-
- ns-1172.awsdns-18.org
- ns-1903.awsdns-45.co.uk
- ns-407.awsdns-50.com
- ns-877.awsdns-45.net
- MX
-
- 10 mx1.forwardemail.net
- 10 mx2.forwardemail.net
- TXT
-
forward-email=openomb@protectdemocracy.org
Email authentication weak
- SPF
-
v=spf1 a include:spf.forwardemail.net include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 125 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
child-src 'self' blob:; frame-src 'self' https://www.youtube.com/embed/ https://apportionment-public.max.gov/ https://pdfobject.com/; worker-src 'self' blob:; connect-src 'self' https://*.sentry.io https://www.google-analytics.com/; font-src 'self'; img-src 'self' data:; script-src 'self' https://browser.sentry-cdn.com https://js.sentry-cdn.com https://cdnjs.cloudflare.com/polyfill/ https://www.googletagmanager.com 'nonce-SENTRY_SCRIPT_SETUP' 'nonce-PROGRESSIVE_JS_CHECK' 'sha256-MS6/3FCg4WjP9gwgaBGwLpRCY6fZBgwmhVCdrPrNf3E=' 'sha256-tQjf8gvb2ROOMapIxFvFAYBeUJ0v1HCbOcSmDNXGtDo=' 'sha256-ZxAi3a7m9Mzbc+Z1LGuCCK5Xee6reDkEPRas66H9KSo=' 'sha256-+5XkZFazzJo8n0iOP4ti/cLCMUudTf//Mzkb7xNPXIc=' 'nonce-LYJXGywIxPX4HyKbhb2eSA=='; style-src 'self' 'unsafe-inline'- strict-transport-security
max-age=31536000; includeSubdomains; preload