orlowlaw.com
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- lh3.googleusercontent.com×16
- deesblcmcahxhemxmsig.supabase.co×2
- cdn.callrail.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- 71-18 Main St, 11367, Kew Gardens Hills, NY, US
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2000-09-29
- Expires
- 2026-09-29 132 days left
- Updated
- 2022-09-01
- Name servers
-
- iris.ns.cloudflare.com
- joel.ns.cloudflare.com
DNS records live
- NS
-
- iris.ns.cloudflare.com
- joel.ns.cloudflare.com
- MX
-
- 0 d339314a.ess.barracudanetworks.com
- 10 d339314b.ess.barracudanetworks.com
- TXT
-
MS=ms62703299google-site-verification=12cno0Sf8HbcjwK3J6a1I3PWxiuLWQz6TleTmW2su1Q
Email authentication weak
- SPF
-
v=spf1 include:spf.ess.barracudanetworks.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 33 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://www.gstatic.com https://cdn.callrail.com https://js.callrail.com https://intaker.azureedge.net https://vercel.live https://api.mapbox.com; style-src 'self' 'unsafe-inline' https://js.callrail.com https://intaker.azureedge.net https://vercel.live https://api.mapbox.com data:; img-src 'self' https://*.supabase.co https://i.ytimg.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://*.googleusercontent.com https://intaker.azureedge.net https://vercel.live https://vercel.com https://*.vercel.com https://api.mapbox.com https://*.tiles.mapbox.com data: blob:; font-src 'self' https://vercel.live; connect-src 'self' https://deesblcmcahxhemxmsig.supabase.co https://www.google-analytics.com https://www.googletagmanager.com https://www.goog- strict-transport-security
max-age=63072000
Links to (5)
- facebook.com×1
- google.com×1
- linkedin.com×1
- twitter.com×1
- youtube.com×1
Linked from (1)
- qcba.org×1