sjmresorts.com
HTML metadata
Technology
- Server
- Tengine
- CMS
- Next.js
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.gstatic.com×3
- fonts.googleapis.com×2
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2017-08-04
- Expires
- 2028-08-04 807 days left
- Updated
- 2025-08-21
- Name servers
-
- vip7.alidns.com
- vip8.alidns.com
DNS records live
- NS
-
- vip7.alidns.com
- vip8.alidns.com
- MX
-
- 10 mail1.sjmresorts.com
- 10 mail2.sjmresorts.com
- TXT
-
Show 16 TXT records
google-site-verification=Yd2jmvaf3uZR6E0d_7J86Xl1EBAI5JR4DOWJ6oHTEvQsophos-domain-verification=927fe85ee875762e3c5cd9d8a6074f26fb371560bfddb5f35eee277df0a918285h6dd58a249levn8hoqv3nnrfcufsn3opvj1ghpgpkcip1840ug6usslra3aivf113hcpo1ues8dcugoogle-site-verification=dAcsiYutFAHCEORnZacdHbrwNeXWcIJLyFveud5630wgoogle-site-verification=PH1Z6xvDYrD0IsqSWWeGA9zcxBTsZJjsalFohNHjRjQMS=A09D1568BB92BAB69B76F3142EDE88E32F8B472Fq0gjr50a5htb38t6cj5sl7s68qfortinet-fortiphish-site-verification=Q6AJt4nGPbhqmemXbqStKcknowbe4-site-verification=cbbe31815a58fbcd8a930fedef73b3a0MS=ms54538311lnmt8fepb41b923k4mh7mhfp27btmunncbomdlik3bjgi2hdpk4i01BXSBJRB7IL8OW7D37TRXIDFZLB60YOK3PQ6OADMS=ms30393384
Email authentication weak
- SPF
-
v=spf1 mx -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 161 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' *.jaoceanus.com *.sjmresorts.com *.grandlisboapalace.com *.kampekmarket.com *.grandlisboa.com *.fontawesome.com *.googletagmanager.com *.facebook.net *.baidu.com *.licdn.com *.googleadservices.com *.googleapis.com *.google.com *.linkedin.com *.facebook.com *.doubleclick.net *.aliyuncs.com o.alicdn.com g.alicdn.com *.tangelo.com.cn; form-action 'self'; object-src 'none'; frame-src 'self' tel: mailto: *.sjmresorts.com *.jaoceanus.com *.grandlisboapalace.com; frame-ancestors 'self' *.jaoceanus.com *.grandlisboa.com *.grandlisboapalace.com *.sjmresorts.com; font-src 'self' data: *.fontawesome.com *.jaoceanus.com *.sjmresorts.com *.grandlisboapalace.com *.kampekmarket.com *.grandlisboa.com fonts.googleapis.com fonts.gstatic.com; img-src 'self' data: *.jaoceanus.com *.sjmresorts.com *.grandlisboapalace.com *.kampekmarket.com *.grandlisboa.com *.googleadservices.com *.googletagmanager.com *.googleapis.com *.google.com *.linkedin.com *.facebook.- strict-transport-security
max-age=31536000- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-site