optumbank.com

.com crawl

First seen 2026-04-23 · Last seen 2026-05-18 · ok HTTP/1.1 200 11692 ms crawled 2026-05-16

US · 149.111.144.242 · AS10879 Unitedhealthcare

Reputation 100/100

Classifying

HTML metadata

Title
Health Savings & Benefits Accounts | Optum Bank
Description
Manage your health care finances with Optum Bank. Explore HSAs, FSAs, HRAs, and investment options to save on medical expenses and plan for the future.
Language
en
Canonical
https://www.optumbank.com

Open Graph

url
https://www.optumbank.com
title
Unlock your health dollars with Optum Bank
description
If you’re looking for ways to make saving for health care easier and more affordable, you’ve come to the right place.
canonicalurl
https://www.optumbank.com

Technology

Third-party hosts loaded (2)

  • assets.adobedtm.com×1
  • nav.optum.com×1

Social

Registration

Registrar
CSC Corporate Domains, Inc.
Created
2008-05-03
Expires
2027-05-03 348 days left
Updated
2026-04-29
Name servers
  • edns4.ultradns.biz
  • edns4.ultradns.com
  • edns4.ultradns.net
  • edns4.ultradns.org
  • epla1.corpnamesvcs.com
  • epla2.corpnamesvcs.com

DNS records live

NS
  • epla1.corpnamesvcs.com
  • epla2.corpnamesvcs.com
MX
  • 5 mxa-0077b904.gslb.pphosted.com
  • 5 mxb-0077b904.gslb.pphosted.com
TXT
  • MS=ms46621555
  • f16bb04e-504b-4dc7-a2d4-a40e1471db3e
  • adobe-idp-site-verification=9a5c47599b4f379d5e29ede339f3da7f9e1689f8e16709c98e397c86a1c68122

Email authentication strong

SPF
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8JmZFlaX54TdA73HwRl4zX6WEp7SOqXrlww9RDkAZLZMGb/JSGbcOOmR1yNIe+QMNixL0+CfsZfGpj…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA OV R36
from 2026-03-24 to 2026-10-09
Expires in 142 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.optumbank.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP uses wildcard sources
  • weak frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN, SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
frame-ancestors 'self' *.uhg.com *.optum.com *.uhc.com *.healthybenefitsplus.com *.adobeaemcloud.com *.pagescdn.com *.healthsafe-id.com uhgenterprise.qualtrics.com g360site.secure.force.com g360.my.salesforce-sites.com *.DoubleClick.net *.youtube.com player.simplecast.com *.trkn.us; frame-src 'self' https://community.pregnancy.org https://optum.marketing.adobe.com *.uhg.com *.optum.com *.uhc.com *.healthybenefitsplus.com *.adobeaemcloud.com *.pagescdn.com *.healthsafe-id.com uhgenterprise.qualtrics.com g360site.secure.force.com g360.my.salesforce-sites.com *.DoubleClick.net *.youtube.com player.simplecast.com *.trkn.us;, frame-ancestors self *.uhg.com *.optum.com *.uhc.com;
strict-transport-security
max-age=31557600

Links to (8)

Linked from (2)