plansponsorlink.com
HTML metadata
Technology
- Fonts
-
- Google Fonts
Third-party hosts loaded (1)
- fonts.gstatic.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2010-07-25
- Expires
- 2027-07-25 432 days left
- Updated
- 2025-07-01
- Name servers
-
- ns1-04.azure-dns.com
- ns2-04.azure-dns.net
- ns3-04.azure-dns.org
- ns4-04.azure-dns.info
DNS records live
- NS
-
- ns1-04.azure-dns.com
- ns2-04.azure-dns.net
- ns3-04.azure-dns.org
- ns4-04.azure-dns.info
- MX
-
- 0 plansponsorlink-com.mail.protection.outlook.com
- TXT
-
MS=ms56927740
Email authentication weak
- SPF
-
v=spf1 ip4:50.57.58.234 ip4:50.57.58.236 include:sendgrid.net ip4:198.37.156.90 ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxMmWekATEhlKQtboGaGbjK6fp2vGkQopONCv3GQeeJZOQKHoX3YmzZ+XlKkGlZrpRCmERj6jz7Ojo18n5B… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDKMAPQo8NPIJEmpAGK/K29c/RSozs1YXVVatg0/YIVlxcU4H8RqZLX3i5Nawy1hkrSP6+1zBxZHd0jtjTpV2xniB…
selectors probed - s1:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 254 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; upgrade-insecure-requests; connect-src 'self' dc.services.visualstudio.com *.pensionpro.com *.applicationinsights.azure.com *.monitor.azure.com *.blob.core.windows.net; style-src 'self' 'unsafe-inline' appcenter.intuit.com *.pensionpro.com fonts.googleapis.com data:; style-src-elem 'self' 'unsafe-inline' appcenter.intuit.com *.pensionpro.com fonts.googleapis.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' appcenter.intuit.com www.googletagmanager.com ajax.googleapis.com ssl.google-analytics.com cdnjs.cloudflare.com az416426.vo.msecnd.net js.braintreegateway.com *.monitor.azure.com; img-src 'self' *.pensionpro.com kendo.cdn.telerik.com data: ssl.google-analytics.com; font-src 'self' fonts.gstatic.com netdna.bootstrapcdn.com data:; frame-ancestors 'self'; frame-src 'self' player.vimeo.com;- strict-transport-security
max-age=31536000