unilock.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (8)
- js.hs-scripts.com×2
- maps.googleapis.com×2
- cdn.cookielaw.org×1
- dc.ads.linkedin.com×1
- static.cloudflareinsights.com×1
- unpkg.com×1
- www.facebook.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- Network Solutions, LLC
- Created
- 1996-01-18
- Expires
- 2031-01-19 1705 days left
- Updated
- 2025-11-20
- Name servers
-
- aisha.ns.cloudflare.com
- miguel.ns.cloudflare.com
DNS records live
- NS
-
- aisha.ns.cloudflare.com
- miguel.ns.cloudflare.com
- MX
-
- 5 mxa-0074d001.gslb.pphosted.com
- 5 mxb-0074d001.gslb.pphosted.com
- TXT
-
Show 7 TXT records
MS=ms46861883duo_sso_verification=pAzmxpLBG9QStYIMgRXiLpG0wdd0VeV9rJLqzZEqXTeflYqFiIrUi0pmAnLyk9Ndfacebook-domain-verification=9ajs1way1ppvyottpk3f3195tyj78ogoogle-site-verification=sp8XZghk9DY2E0q3L-esdnikAfG_wnhzyPPCVHIp6EYgoogle-site-verification=xQu2wOs1hG0XxgYQeXDKLPsX1fl3klLv0s4jY_coBDsov4dlq6tt3ehnnjfpvvrk198k1v=jmp1i90e1u001p3n7nob0flbbt
Email authentication strong
- SPF
-
v=spf1 include:spf-0074d001.pphosted.com include:_spf.ultipro.com include:spf.ca.exclaimer.net include:spf.protection.outlook.com include:43700251.spf02.hubspotemail.net include:app.teamsupport.com include:_spf.syonex.com ip4:99.209.98.70 ip4:216.126.78.210 ip4:72.138.35.73 ip4:72.138.36.210 ip4:12.167.248.84 ip4:12.167.248.82 ip4:12.167.248.85 ip4:72.138.35.78 ip4:12.167.248.86 ip4:72.138.35.65 ip4:72.138.35.79 ip4:68.171.172.82 ip4:104.196.5.66 ip4:52.204.234.254 ip4:52.86.165.143 ip4:54.240.122.88 ip4:10.131.140.24 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:spamfilter@unilock.compolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCNY/cYJ3wKQky3UQUBodiVT7EZ/D96Etf3jxDH2fkAlwgfOndxvMmt/Th96QEj7tNIirYL9Nug5C8jggZvFk… - selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC61iQlR8bCQumFvTbOE/CezYRarVqjM78TufBHkMR1VikcHHmwj+Ag7rjh1fspqlGgdkTxLjjIq/dr6bR/xq… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCuNLBBjnEJLpBy28z28B9Pl/xzZfOcwl+UUdcRzhNvhs0npDfdECwTMlT5Ir631d21UJkUTEJAXJHs7ry3A4…
selectors probed - google:
Certificate (current)
WE1
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
origin- permissions-policy
geolocation=self- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src 'self' data: http: https: wss://*.luckyorange.com *.luckyorange.com *.pinimg.com *.stackadapt.com ipv4.pdscrb.com *.gravatar.com *.googletagmanager.com *.google-analytics.com *.hubspot.com *.hsappstatic.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: googleapis.com gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.googletagmanager.com https://www.googletagmanager.com *.google-analytics.com *.gstatic.com https://js.hsforms.net https://js.hs-scripts.com; style-src 'self' 'unsafe-inline' blob: http: https: fonts.googleapis.com; font-src 'self' data: http: https: fonts.googleapis.com themes.googleusercontent.com; frame-src 'self' https: cdn.flipsnack.com *.google.com gtranslate.io https://contractor.unilock.com https://forms.hscollectedforms.net facebook.com connect.facebook.com https://js.hsforms.net https://forms.hscollectedforms.net; connect-src 'self' wss://*.luckyorange.com *.luckyorange.com *.pinimg.com *.stackadapt.com ipv4.pdscrb- strict-transport-security
max-age=63072000- cross-origin-opener-policy
origin-allow-popups- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-site