soligenix.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- jQuery
- 3.6.4
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- cdnjs.cloudflare.com×2
- fonts.googleapis.com×2
- www.google.com×2
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2009-09-11
- Expires
- 2026-09-11 101 days left
- Updated
- 2025-09-11
- Name servers
-
- ns51.domaincontrol.com
- ns52.domaincontrol.com
DNS records live
- NS
-
- ns51.domaincontrol.com
- ns52.domaincontrol.com
- MX
-
- 0 soligenix-com.mail.protection.outlook.com
- TXT
-
4qogsr3eslaf5n4rbemoemf6e6
- Verified for
-
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com v=spf1 include:spf.maropost.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDV37ViPSDKA47nSZwc+gVo/XaLKiZeiwNSJMzyLtOie7VKjFxT/jMM7WTX2Mq//NV5ezSVWxSJh7fvd… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApekx3o5wV6vb+5paBuD2lDziFC7gW70Gy+c6mYMYqEZAmvnGvxesLuLXlNH1t3w+XwJww005W6pX0f…
selectors probed - default:
Certificate (current)
R3
Expired 1682 days ago
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
child-src 'self' ; connect-src 'self' *.google-analytics.com *.wpengine.com yoast.com *.google.com *.g.doubleclick.net *.youtube.com *.google-analytics.com *.wpengine.com yoast.com *.google.com *.g.doubleclick.net ; default-src 'self' ; font-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.gstatic.com *.bootstrapcdn.com *.gstatic.com *.bootstrapcdn.com ; form-action 'self' ; frame-src 'self' *.g.doubleclick.net *.google.com *.fls.doubleclick.net *.youtube.com *.g.doubleclick.net *.google.com *.fls.doubleclick.net ; frame-ancestors 'self' ; img-src 'self' 'unsafe-inline' data: *.googletagmanager.com *.w.org *.gravatar.com *.google.com *.google-analytics.com *.gstatic.com *.ytimg.com *.googletagmanager.com *.w.org *.gravatar.com *.google.com *.google-analytics.com *.gstatic.com ; manifest-src 'self' ; media-src 'self' ; navigate-to 'self' ; object-src 'self' ; script-src 'self' *.cloudflare.com *.g.doubleclick.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstati- strict-transport-security
max-age=63072000; includeSubdomains; preload- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none