thephotographyinstitute.com
HTML metadata
Technology
- Server
- nginx
- jQuery
- 3.3.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (8)
- player.vimeo.com×3
- analytics.ahrefs.com×1
- challenges.cloudflare.com×1
- code.jquery.com×1
- fonts.googleapis.com×1
- maxcdn.bootstrapcdn.com×1
- widget.trustpilot.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2007-02-19
- Expires
- 2027-02-19 261 days left
- Updated
- 2025-12-13
- Name servers
-
- ns-1384.awsdns-45.org
- ns-1877.awsdns-42.co.uk
- ns-469.awsdns-58.com
- ns-577.awsdns-08.net
DNS records live
- NS
-
- ns-1384.awsdns-45.org
- ns-1877.awsdns-42.co.uk
- ns-469.awsdns-58.com
- ns-577.awsdns-08.net
- MX
-
- 10 mail.thephotographyinstitute.com
- TXT
-
Validity-Domain-Verification=WYcLiZGvOMo7mSzweDy8GLejgvU=
- Verified for
-
- Ahrefs
- Apple
- Yahoo
Email authentication strong
- SPF
-
v=spf1 a mx ip4:64.140.165.142 ip4:64.140.165.133 ip4:64.140.166.218 include:transmail.net.au ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_aggrepts@thephotographyinstitute.com; ruf=mailto:dmarc_forensicrepts@thephotographyinstitute.com; fo=1; pct=100; rf=afrfpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 72 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src blob: *; child-src blob: *; img-src 'self' data: https: blob: https: *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' blob: https: *; worker-src 'self' 'unsafe-inline' blob: https: *;