pvhcd.org

.org crawl

First seen 2026-05-30 · Last seen 2026-05-31 · ok HTTP/1.1 200 2152 ms crawled 2026-05-31

US · 104.21.50.40 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Home Page | Pajaro Valley Health Care District
Language
en
Generator
Drupal 11 (https://www.drupal.org)
Canonical
https://www.pvhcd.org/

Open Graph

title
Home Page
site name
Pajaro Valley Health Care District

Technology

CDN
Cloudflare
CMS
Drupal

Third-party hosts loaded (2)

  • static.addtoany.com×1
  • translate.google.com×1

DNS records live

NS
  • gail.ns.cloudflare.com
  • marvin.ns.cloudflare.com
MX
  • 0 pvhcd-org.mail.protection.outlook.com
TXT
  • ppe-3fbc0c4634a757501ee6b941dd9e6b7ab75fb59e
Verified for
  • Microsoft 365

Email authentication partial

SPF
v=spf1 a:dispatch-us.ppe-hosted.com include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:991bde01b0ae.a@dmarcinput.com; ruf=mailto:991bde01b0ae.f@dmarcinput.com; sp=none; fo=1
policy: none (monitoring only) · sp=none
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-05-03 to 2026-08-01
Expires in 61 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.pvhcd.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • permissions-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
Header values
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), attribution-reporting=(), autoplay=*, bluetooth=(), browsing-topics=(), camera=(), compute-pressure=(), display-capture=*, encrypted-media=(), geolocation=(), gyroscope=(), hid=(), identity-credentials-get=(self), idle-detection=(), local-fonts=(self), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=*, publickey-credentials-get=(self), screen-wake-lock=(), serial=(), storage-access=(), usb=(), web-share=(), window-management=(), xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' * blob: data:; script-src * about: 'unsafe-inline' 'unsafe-eval'; object-src 'self'; style-src * 'unsafe-inline'; img-src * data: blob:; media-src * blob: data:; frame-ancestors 'self'; upgrade-insecure-requests
strict-transport-security
max-age=2592000

Links to (3)

Linked from (1)