streck.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- jQuery
- 3.6.0
- Analytics
-
- Google Analytics
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (10)
- cxppusa1formui01cdnsa01-endpoint.azureedge.net×2
- fonts.googleapis.com×2
- mktdplp102cdn.azureedge.net×2
- fonts.gstatic.com×1
- gmpg.org×1
- www.google-analytics.com×1
- www.google.com×1
- www.googletagmanager.com×1
- www.vimeo.com×1
- www.youtube.com×1
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1996-06-29
- Expires
- 2029-06-28 1119 days left
- Updated
- 2024-05-03
- Name servers
-
- fay.ns.cloudflare.com
- hank.ns.cloudflare.com
DNS records live
- NS
-
- fay.ns.cloudflare.com
- hank.ns.cloudflare.com
- MX
-
- 0 streck-com.mail.protection.outlook.com
- TXT
-
M7lyBIiD2eGD+oELl0fUI7pUPSAHd/pIMqCS0H8xWOOddH9Afn6Hyb4UwRINJQVkbNyFqbU8N2LB4xyxEbhd5g==remarkable-domain-verification=40f8da3c-4059-428f-a470-ac360694e678nintex.6459654fc6d6e74e348df25f
- Verified for
-
- Anthropic
- DocuSign
- Dynamics 365
- OpenAI
- Smartsheet
- Zoom
Email authentication partial
- SPF
-
v=spf1 a mx ip4:64.253.161.66 ip4:208.43.221.192/29 ip4:174.36.15.16/29 ip4:213.206.105.68/30 ip4:66.240.227.4 ip4:66.240.227.9 ip4:66.240.227.18 ip4:66.240.227.21 ip4:63.143.57.132 ip4:63.143.57.137 ip4:63.143.57.146 ip4:63.143.57.149 ip4:208.86.168.7 ip4:206.152.14.54 ip4:174.128.1.123 ip4:206.152.14.54 ip4:107.20.210.250 ip4:52.1.14.157 ip4:107.23.16.222 ip4:54.173.83.138 ip4:4.7.65.146 ip4:66.37.242.202 ip4:64.253.161.66 include:spf.protection.outlook.com include:_spf.act-on.net include:_spf.ultipro.com include:spf.agiloft.com include:spf-us.emailsignatures365.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwjl3bdh/Vem12jbvd1igx7jpX0aNUD9WxolUEfu4YzNpc1aVO6JFvs9952sBApVkJ1MS+TRvlLQD4/… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDW1a4K4N5KWEtT9aWfpJRZWu8sTebBURvdkv8zssYOHl5B49X6NFLnWc8g6ymVxiPe1imzXl6qVMjEvlfqmP…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 73 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src * data: blob: 'unsafe-inline'; img-src * data: blob:; font-src * data: blob:; connect-src * data: blob:; frame-src * data: blob:;- strict-transport-security
max-age=63072000; includeSubDomains; preload, max-age=63072000; includeSubDomains; preload