paulhastings.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- images.ctfassets.net×4
- www.googletagmanager.com×4
Social
DNS records live
- NS
-
- pdns1.ultradns.net
- pdns2.ultradns.net
- pdns3.ultradns.org
- pdns4.ultradns.org
- pdns5.ultradns.info
- pdns6.ultradns.co.uk
- udns1.ultradns.net
- udns2.ultradns.net
- MX
-
- 10 mxa-000e5303.gslb.pphosted.com
- 10 mxb-000e5303.gslb.pphosted.com
- TXT
-
Show 7 TXT records
box-domain-verification=1d6cdbdb0e6a2c6548dc13cd388083f1ccb712ef2883370ef2ddb7fed64369fdlogmein-verification-code=30e1ed0a-41a3-4c0f-8463-857664efadffciscocidomainverification=1330de3349c2e88dcd089bc882809c083edfd97684460d18aa9d706628a7033chave-i-been-pwned-verification=dweb_fh0xjjgxic6h56vho6mxxgnzpI3AFofJSUe0K4x6LofGeXIyFe9TFdH3jV+nMcicBoJnVix4cMVHWoh3m8II8w0OmdtIdpUUQ87hoG3iad0bGA==apperio-domain-verification=1e1d00b6ed6f4184a48a76f13a7cfa7dpardot966853=6a104c2e7167c88ae6a49a66d86c0f95592af988b98a69df65e8f30857fc2395
- Verified for
-
- Adobe
- Apple
- DocuSign
- Dropbox
- Sitecore
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 80 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
img-src 'self' data: i.vimeocdn.com images.ctfassets.net p.typekit.net cdn.userway.org cdn77.api.userway.org t.influ2.com/p/vt/ https://www.google-analytics.com/collect https://i.ytimg.com/vi_webp/; media-src 'self' assets.ctfassets.net videos.ctfassets.net downloads.ctfassets.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.userway.org https://cdn.userway.org/widget.js https://www.googletagmanager.com/gtag/js https://use.typekit.net/nvk1yiz.js https://pi.pardot.com/analytics https://pi.pardot.com/pd.js http://cdn.pardot.com/pd.js https://www.googletagmanager.com/gtm.js https://www.google-analytics.com/analytics.js https://cdn.yoshki.com/yoshki-library.js https://www.influ2.com/tracker https://insights.paulhastings.com/analytics report-sample https://cdn.jsdelivr.net; font-src 'self' data: use.typekit.net cdn.userway.org; style-src 'self' 'unsafe-inline' use.typekit.net p.typekit.net cdn.userway.org https://cdn.userway.org/styles https://cdn.userway.org/widgetapp/bundles/udf/ud- strict-transport-security
max-age=31536000; includeSubDomains