ottocap.com
HTML metadata
Technology
- Server
- nginx
- JS framework
- Angular 19.2.21
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (5)
- fonts.googleapis.com×2
- s3-us-west-2.amazonaws.com×2
- cdn1.stamped.io×1
- fonts.gstatic.com×1
- player.vimeo.com×1
Social
Contact
- Address
- 3550-A Jurupa Street, 91761, Ontario, CA, US
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1997-07-30
- Expires
- 2028-07-29 788 days left
- Updated
- 2023-05-24
- Name servers
-
- carol.ns.cloudflare.com
- lloyd.ns.cloudflare.com
DNS records live
- NS
-
- carol.ns.cloudflare.com
- lloyd.ns.cloudflare.com
- MX
-
- 0 ottocap-com.mail.protection.outlook.com
- TXT
-
pq521k16SEobk6WQCdIsVyPqwrK4i4crRS96kvBwmEDJbZ9cYk0BLLE45XnTyQo1lW7kFNnjcMv7OVDly2Z5Xg==bqgh7ttmbz72kfmkbghkph002tzxtzpr
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 a:mailin1.ottocap.com a:mailin2.ottocap.com ip4:12.0.227.18 ip4:66.146.63.92 ip4:12.0.225.210 include:servers.mcsv.net include:spf.protection.outlook.com include:48233391.spf10.hubspotemail.net -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@ottocap.com; ruf=mailto:dmarc@ottocap.com; fo=1; rf=afrf; pct=100;policy: reject (enforced) - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCI6nT5dDOww9TxuQv3/gPGPcabk5qLWey8vYktoEqGmIeCfaxUNjbc9tZnGngBR1AjFGt74HoAp3VTA6q3sU… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkBkX2OLgRNfj5wEHwS8yVrnQxX5hnt8JSCFzGUXM9mVI5z6Ny6+L45yGA4ppkfSbPwPs3PuzuYYMRJazZLD… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoxIBZZG8C4G6KTPyxGmw8U7jYN/bnjwUmLldXAI2yQ4JmkJExQibUoxtrP7y+REkv1qtQCHAwGtdWyqlKC… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDN2kb4TR4ekUVXHREcsvnsbIsUOLirnUOKoDP75THH+0kFM89uuIInI5UVLPwA1AGY6WMhfa8UReaTjDBqS0rfVU…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M01
Expires in 154 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn1.stamped.io/ https://*.cloudfront.net; font-src 'self' https://fonts.gstatic.com https://cdn1.stamped.io/ https://cdn.livechatinc.com data:; img-src 'self' data: blob: https://s3-us-west-2.amazonaws.com/ https://googleads.g.doubleclick.net/ https://www.facebook.com https://www.google.com/ https://track-na2.hubspot.com/ https://c.bing.com/ https://vumbnail.com/ https://cdn.stamped.io/ https://48233391.fs1.hubspotusercontent-na1.net/ https://ottocap.s3.us-west-2.amazonaws.com/ https://www.google.co.in/ https://app.hubspot.com/ https://*.clarity.ms https://forms.hsforms.com/ https://track.hubspot.com/ https://textrenderer.salesonepro.com https://*.cloudfront.net https://www.google-analytics.com/ https://www.googletagmanager.com/ https://ottocap.s3.amazonaws.com http://i2.ytimg.com https://ui-avatars.com https://maps.gstatic.com https://cdn.livechatinc.com; script-src 'self' 'unsafe-inline' 'un- strict-transport-security
max-age=15768000; includeSubDomains