tcfcu.com

.com crawl

First seen 2026-05-02 · Last seen 2026-05-15 · ok HTTP/1.1 200 2727 ms crawled 2026-05-09

US · 54.235.207.216 · AS14618 Amazon.com, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Town & Country Federal Credit Union - Southern Maine's Credit Union - TCFCU
Description
We are a Southern Maine credit union promoting financial wellness. Join us for checking, savings, loans and helpful financial information. Save money and earn more.
Language
en-US
Generator
WordPress 6.4.3
Canonical
https://www.tcfcu.com/
Feeds

Open Graph

url
https://www.tcfcu.com/
title
Town & Country Federal Credit Union - Southern Maine's Credit Union - TCFCU
locale
en_US
site name
Town & Country Federal Credit Union
description
We are a Southern Maine credit union promoting financial wellness. Join us for checking, savings, loans and helpful financial information. Save money and earn more.
updated time
2026-05-01T10:10:31-04:00

Technology

CMS
WordPress
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • www.google.com×2
  • maps.googleapis.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

Registration

Registrar
Network Solutions, LLC
Created
1997-08-08
Expires
2034-08-07 3000 days left
Updated
2024-10-22
Name servers
  • ns91.worldnic.com
  • ns92.worldnic.com

DNS records live

NS
  • ns91.worldnic.com
  • ns92.worldnic.com
MX
  • 10 mx.usa.net
  • 20 mx.ct.mbox.net
  • 99 d91155a.ess.barracudanetworks.com
  • 99 d91155b.ess.barracudanetworks.com
TXT
Show 5 TXT records
  • JpoLRWDfaW3AGrPdj5tBowG5GanAL5hPFfYuEnqbRfHkL7hyv6zMRSB1H/MnEWmeCCQ/GOD08IaMrJHVdTReNw==
  • v=s54b2ok6dakemor9ujer9gjd74
  • amazonses:3M1+nK87GbkBiNDTwThiPtD+zU9P/rg3rXVAwSzRi98=
  • k55ai88ug1bkpfl5hauqe90rap
  • _synk6vw8guklfcali4whrz2ul8uot1g
Verified for
  • Google
  • Microsoft
  • Microsoft 365

Email authentication partial

SPF
v=spf1 ip4:68.232.131.30 ip4:68.232.140.103 ip4:68.232.143.79 ip4:68.232.149.148 ip4:209.222.82.0/24 include:spf.protection.outlook.com include:spf.usa.net include:spf.cashedge.com include:vertifi.com include:_spf.btbpo.net include:dnsexit.com include:45636858.spf07.hubspotemail.net ip4:148.163.159.19 ip4:148.163.157.19 ip4:148.163.152.17 ip4:148.163.148.172 ip4:148.163.148.183 ip4:148.163.152.60 ip4:63.114.195.39 ip4:63.114.195.237 ip4:12.164.193.34 ip4:12.164.193.235 ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:tcadmin@tcfcu.com; adkim=r; aspf=r; pct=100; rf=afrf; ri=86400
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAKK2/OvQ9HZdcMF5rrbe9J1kZLeeh7vo/OzKl07H2g7rzBYEpGe426+R2CZe+BzXeO1BkJLMgcCivfA6FJ9…
selectors probed

Certificate (current)

E8
from 2026-03-22 to 2026-06-20
Expires in 30 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.tcfcu.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' https://fonts.bunny.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn25.lemnisk.co https://js.hs-banner.com https://js.hscollectedforms.net https://js.hsadspixel.net https://js.hs-analytics.net https://js-na1.hs-scripts.com https://snap.licdn.com https://*.adroll.com https://*.google.com https://*.lemnisk.co https://www.googletagmanager.com https://www.gstatic.com https://maps.googleapis.com https://teachbanzai.com https://banzai.org https://assets.banzai.org https://reports.hrmdirect.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://connect.facebook.net https://js.poshdevelopment.com https://collector-14314.us.tvsquared.com https://api.alpharank.io https://tags.srv.stackadapt.com https://cdn.woobox.com https://www.youtube.com https://px.premion.com https://static.hsappstatic.net https://lex.33across.com https://js.hsforms.net; style-src 'self' 'unsafe-inline' https://*.googleapis.com https
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (7)

Linked from (1)