thecitizensbank.net
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Termly
- Fonts
-
- Font Awesome
- Google Fonts
Third-party hosts loaded (10)
- assets.juicer.io×2
- fonts.googleapis.com×2
- image-proxy.teamsi.com×2
- app.termly.io×1
- kit.fontawesome.com×1
- maps.googleapis.com×1
- use.fontawesome.com×1
- www.fdic.gov×1
- www.googletagmanager.com×1
- www.juicer.io×1
Social
Contact
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 1998-03-16
- Expires
- 2027-03-15 299 days left
- Updated
- 2026-02-13
- Name servers
-
- elmo.ns.cloudflare.com
- evangeline.ns.cloudflare.com
DNS records live
- NS
-
- elmo.ns.cloudflare.com
- evangeline.ns.cloudflare.com
- MX
-
- 10 thecitizensbank-net.mx1.arsmtp.com
- 20 thecitizensbank-net.mx2.arsmtp.com
- TXT
-
Show 8 TXT records
MS=AB57359ED3AC2CED2C6C339097F6D86BCBCBE6C6MS=ms78267970a5d51931e31324744b41c2d04423242fapple-domain-verification=FByO65Ga2L5v8McGbTBDmSfufacebook-domain-verification=t6mqioqx4lgfwu66olk6ohyhimy1shgoogle-site-verification=xrMaPQd127pdYIYYxcO0verhjkN5iQqAzcrxdrDDt44qjl8q01m2pmkluivr0blp1qhpe
Email authentication strong
- SPF
-
v=spf1 ip4:216.116.80.0/20 ip4:74.200.32.0/19 ip4:149.72.198.89/32 ip4:185.148.46.219/32 ip4:52.128.64.0/18 ip4:23.101.119.44/32 include:spf.teslarsoftware.com include:spf.protection.outlook.com include:spfref.jackhenry.com include:amazonses.com include:spf-us.emailsignatures365.com include:spf-westus.emailsignatures365.com include:finboa.com include:mailgun.org include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:DMARC@thecitizensbank.net; ruf=mailto:citizensbank-dmarc@datafeeds.phishlabs.com,mailto:ComputerSupport@thecitizensbank.net;policy: quarantine - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC2jjuvANHe8vx/NUTCs7ML3FOa3boKEGSIvYQQJn5fPPTvCOCBfwz95MH1ZN6utGPTe7SI9ZTaPRr2hZBJAK… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwJHgIqt+RP90oKjxctos82sSVhkV2xcebDOwFdrPKBm9vdqNXkbjqn2EF6jQYXTjoInNGQ6yODXFmU… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4k0ZLIHv9SAKGASmKC2VNQoD2gOBK6NmkSRN1vsFM7kSbQ/VSpzcpuvsscvisZzXDRjZu01RBXm3hszFPw… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv6IrIzLsoJRBJWDSVrnuO57pZ4pk9SPrKkIj0i7Lgs+1SpiIrPkhuUnEwAepbucpN0DsMAxxnrHYnFHZZn…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 80 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), camera=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), browsing-topics=()- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'self' 'unsafe-inline' *.timevaluecalculators.com/ 'unsafe-eval' *.fdic.gov *.s3.us-gov-west-1.amazonaws.com *.mathtag.com *.userway.org *.googleapis.com *.gstatic.com www.google.com *.google-analytics.com apis.google.com *.cookiepro.com *.doubleclick.net *.termly.io termly.io app.termly.io *.juicer.io *.acsbapp.com acsbapp.com *.licdn.com *.hotjar.com *.googletagmanager.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com/iframe_api platform.twitter.com *.simpli.fi https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com https://platform.stumbleupon.com/1/widgets.js https://cdn.insight.sitefinity.com https://dec.azureedge.net/ https://api.userway.org/ https://cdn.userway.org/ https://api.userway.org/api/tunings/CYKa2fXuBk munchkin.marketo.net *.eloqua.com js.hs-scripts.com js.hs-analytics.net *.en25.com cdn.ampproject.org *.jquery.com *.fontawesome.com *.addthis.com *.marketingautoma- strict-transport-security
max-age=31536000