significancemagazine.com
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- 123-Reg Limited
- Created
- 2009-07-23
- Expires
- 2026-07-23 62 days left
- Updated
- 2025-07-24
- Name servers
-
- mdns1.hostwindsdns.com
- mdns2.hostwindsdns.com
DNS records live
- NS
-
- mdns1.hostwindsdns.com
- mdns2.hostwindsdns.com
- TXT
-
Probely=9a6362ad-f51a-45ad-877e-8ba7fd6861d4
Email authentication no MX
- SPF
-
v=spf1 +mx +a +ip4:192.236.146.177 ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4lx6FgNqliGXNN1mGNQE5OkafBlCLKpMfqZ6sFGfuFuDy8oSjOQgPygUal+cahERYvmKcBQdXZvAkP…
selectors probed - default:
Certificate (current)
R12
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- weak frame protection
- weak content type protection
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(self), encrypted-media=(), fullscreen=*, geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=*, usb=(), xr-spatial-tracking=(), gamepad=(), serial=(), accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(self), encrypted-media=(), fullscreen=*, geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=*, usb=(), xr-spatial-tracking=(), gamepad=(), serial=()- x-content-type-options
nosniff, nosniff- content-security-policy
upgrade-insecure-requests; form-action 'self'; img-src 'self' data:; frame-src 'self' https://youtube.com; worker-src 'self' https://clientcdn.pushengage.com; manifest-src 'self'; media-src 'self'; connect-src 'self' https://a.pusheapi.com https://clients-api.pushengage.com https://web-sdk.pushengage.com https://clientcdn.pushengage.com https://yoast.com https://region1.google-analytics.com https://google-analytics.com https://googletagmanager.com; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com; object-src 'self'; base-uri 'self'; report-uri https://67b4547341b27f3460ec296c.endpoint.csper.io/?v=1;, upgrade-insecure-requests; form-action 'self'; img-src 'self' data:; frame-src 'self' https://youtube.com; worker-src 'self' https://clientcdn.pushengage.com; manifest-src 'self'; media-src 'self'; connect-src 'self' https://a.pusheapi.com https://clients-api.pushengage.com https://web-sdk.pushengage.com https://clientcdn.pushengage.com https://yoast.com https:/- strict-transport-security
max-age=63072000; includeSubDomains, max-age=63072000; includeSubDomains- cross-origin-opener-policy
unsafe-none, unsafe-none- cross-origin-embedder-policy
unsafe-none; report-to='default', unsafe-none; report-to='default'- cross-origin-resource-policy
cross-origin, cross-origin
Links to (5)
- amstat.org×2
- facebook.com×2
- oup.com×2
- rss.org.uk×2
- twitter.com×2