roughriverhardware.com
HTML metadata
Technology
- jQuery
- 1.9.1 known XSS (<3.5)
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- b.bongo4u.com×8
- ajax.googleapis.com×1
- cdnjs.cloudflare.com×1
- common.emerge2.com×1
- fonts.googleapis.com×1
Social
Contact
- Phone
- Address
- 9307 South Highway 259, 40152, McDaniels, KY, US
Registration
- Registrar
- Network Solutions, LLC
- Created
- 2013-07-28
- Expires
- 2026-07-28 52 days left
- Updated
- 2024-06-16
- Name servers
-
- ns10.wixdns.net
- ns11.wixdns.net
DNS records live
- NS
-
- ns10.wixdns.net
- ns11.wixdns.net
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 30 alt2.aspmx.l.google.com
- 40 alt3.aspmx.l.google.com
- 50 alt4.aspmx.l.google.com
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 include:_spf.google.com include:_spf.emerge2.com a:smtp5.volusion.com include:sendgrid.net ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 67 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- missing Content Security Policy
Header values
- referrer-policy
origin, unsafe-url- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=(self)- x-content-type-options
nosniff- strict-transport-security
max-age=2592000- content-security-policy-report-only
default-src 'self' data: 'unsafe-inline' b.bongo4u.com; script-src 'self' data: 'unsafe-inline' b.bongo4u.com blob: 'unsafe-eval' bongo4u.com *.bongo4u.com *.emerge2.com *.google.com *.gstatic.com *.google-analytics.com *.googleapis.com *.googleusercontent.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com *.yahooapis.com *.mailchimp.com *.list-manage.com chimpstatic.com *.ipify.org jsonip.com *.amazonaws.com/downloads.mailchimp.com/ *.jquery.com *.hotjar.com acsbapp.com *.bootstrapcdn.com googleads.g.doubleclick.net *.elfsight.com *.createsend1.com *.roomvo.com; connect-src 'self' data: 'unsafe-inline' b.bongo4u.com comments.emerge2.com util.emerge2.com bongo4u.com *.emerge2.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.ca *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.doubleclick.net *.facebook.com *.hotjar.io *.hotjar.com acsbapp.com *.acsbapp.com *.elfsight.com createsend.com *