thecalli.org

.org crawl

First seen 2026-05-02 · Last seen 2026-05-09 · ok HTTP/1.1 200 4912 ms crawled 2026-05-09

US · 3.33.251.168 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
calli
Language
en-US

Open Graph

url
https://www.thecalli.org/
title
calli
description
We are excited to offer space to non-profits at our North Oakland community hub: The Omni

Technology

Server
ESF
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • fonts.googleapis.com×4
  • lh3.googleusercontent.com×4
  • www.gstatic.com×2
  • apis.google.com×1

Contact

Email

DNS records live

NS
  • ns35.domaincontrol.com
  • ns36.domaincontrol.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • google-site-verification=6x5zv_gdAph0aRcYizsFoVQJILlsxLKjlw1LCaJkQD8

Email authentication weak

SPF
v=spf1 include:dc-aa8e722993._spfm.thecalli.org ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

Go Daddy Secure Certificate Authority - G2
from 2025-08-06 to 2026-08-06
Expires in 79 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.thecalli.org

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-WBH5P-5DGouO67s3R7T04Q' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/
cross-origin-opener-policy
unsafe-none
cross-origin-resource-policy
same-site

Links to (1)

Linked from (1)