ultimadisplays.com
HTML metadata
Technology
- Server
- Microsoft-IIS
- CMS
- Ghost
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (7)
- www.googletagmanager.com×2
- cdn.cookie-script.com×1
- fonts.googleapis.com×1
- kit.fontawesome.com×1
- my.matterport.com×1
- r1-t.trackedlink.net×1
- www.youtube.com×1
Contact
Registration
- Registrar
- Register SPA
- Created
- 2018-06-03
- Expires
- 2027-06-03 367 days left
- Updated
- 2025-06-03
- Name servers
-
- ns0.lcn.com
- ns1.lcn.com
- ns2.lcn.com
DNS records live
- NS
-
- ns0.lcn.com
- ns1.lcn.com
- ns2.lcn.com
- MX
-
- 0 ultimadisplays-com.mail.protection.outlook.com
- TXT
-
Show 5 TXT records
zghvz1qbf2l7qw9mqd3gc3f9lzs5p7hfn86nj21bgrdb31l3k6nwxvc5wpqpxky8_qp7cvket1d5g3xq9h1ltyms25ms4cfpf9dq7gyy78wpzskvm7l4m9m869lxg2m8_js2o3qvbqfqnk5trc9kj28x5pt5068c
- Verified for
-
- Apple
- Dynamics 365
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:88.212.138.68 include:spf.protection.outlook.com include:spf.UK.exclaimer.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:supportnotifications@bright-cloud.net; ruf=mailto:supportnotifications@bright-cloud.net; fo=1policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuvQWzJNUuOqhLARrJCqx0K9/zrbhhbPrjt29tdIBWiqy0fgsWKQh4Un2o6wOId9U6AfgKJ0r91Fe+R…
selectors probed - selector1:
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 86 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=*, usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src *; font-src * data:; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; worker-src blob:;- strict-transport-security
max-age=31536000; includeSubDomains