tronox.com
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- fonts.googleapis.com×4
- fonts.gstatic.com×2
- consent.cookiebot.com×1
- gmpg.org×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- SafeNames Ltd.
- Created
- 2004-06-11
- Expires
- 2026-10-16 150 days left
- Updated
- 2024-11-01
- Name servers
-
- ns1-07.azure-dns.com
- ns2-07.azure-dns.net
- ns3-07.azure-dns.org
- ns4-07.azure-dns.info
DNS records live
- NS
-
- ns1-07.azure-dns.com
- ns2-07.azure-dns.net
- ns3-07.azure-dns.org
- ns4-07.azure-dns.info
- MX
-
- 10 tronox.in.tmes-anz.trendmicro.com
- TXT
-
Show 11 TXT records
8t3z5d9l7x0wznpz251yp06htpbvxh2ph4jc1x95gg6l15jzb66hv1jy1w34lhb3apple-domain-verification=TBRKmfgQynTfoe4Matlassian-domain-verification=D6bym3bZKtZCIMohoNdmavFnmadOyqv/fuf3dOKZBp2SnKc61O2l8lnMgXyRVx5jatlassian-sending-domain-verification=76e0af70-8c75-44e6-a75f-7c2aa325af35google-site-verification=g1n51B8WvGcExABjiQfCsMamsCX1QIcm9gu4PJsdGbkMS=ms51670775HKCc9T+xjJ66yrFNW/XWBXn6V6tWW4RMlr2xhaRd623Wmj2bC85CU6QGgUOzug1EMVZQc9vopYJ/stW2vddXmA==mt-37916735tmes=40aa29df80d91e48e2a0fc3ac0de0a4dZOOM_verify_SbbTTDt1TKmiGNJhpRRtOw
Email authentication strong
- SPF
-
v=spf1 ip4:203.161.120.243 ip4:38.89.225.46 ip4:20.114.150.9 ip4:20.29.65.44 ip4:38.124.38.0/26 include:spf.protection.outlook.com include:spf.tmes.trendmicro.com include:_spf-sfdc.successfactors.com include:_spf.atlassian.net include:_spf.salesforce.com -allstrict (-all) - DMARC
-
v=DMARC1;p=none;sp=none;pct=100;rua=mailto:DMARC@tronox.com;ruf=mailto:DMARC@tronox.com;ri=86400;aspf=r;adkim=r;fo=1policy: none (monitoring only) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), interest-cohort=(), layout-animations=(), legacy-image-formats=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), oversized-images=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-script=(), sync-xhr=(), usb=(), vertical-scroll=(), web-share=(), wake-lock=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' https: data:; connect-src 'self' https:; font-src 'self' https: data:; media-src 'self'; report-uri 'self'; child-src 'self'; form-action 'self' https:; frame-ancestors 'self'; object-src 'self'; frame-src 'self' https:; worker-src 'self' blob:; manifest-src 'self'; navigate-to 'self'; prefetch-src 'self'; base-uri 'self'; block-all-mixed-content; upgrade-insecure-requests- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-resource-policy
same-site