pbgfl.gov
HTML metadata
Technology
- jQuery
- 3.7.1
- Stack
- ASP.NET
Third-party hosts loaded (5)
- docaccess.com×1
- translate.google.com×1
- webchat-ui.citibot.net×1
- www.facebook.com×1
- www.instagram.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns77.domaincontrol.com
- ns78.domaincontrol.com
- MX
-
- 0 d329281a.ess.barracudanetworks.com
- 1 d329281b.ess.barracudanetworks.com
- TXT
-
Show 4 TXT records
knowbe4-site-verification=cdfd99a1e99660b47b0d88b0c5978038amazon-business-verification=28f38184582ed55e3cd89d7abff08b61b76d3549c2d743e1af42f8ceabc29ba9ZA=JxGBZuG51G/xd8EWAxSM/Q==v=spf1 ip4:151.132.106.163 ip4:50.78.116.113 include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com include:_spf.vivantio.com include:sendgrid.net -all
- Verified for
-
- Apple
- DocuSign
Certificate (current)
R12
Expires in 65 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://*.granicus.com https://platform.civicplus.com https://account.civicplus.com https://analytics.civicplus.com; img-src * data: blob:; worker-src * data: blob: 'unsafe-eval' 'unsafe-inline'; script-src * about: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; media-src * blob:; font-src * data:; default-src *