websterbank.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
- Fonts
-
- Google Fonts
Third-party hosts loaded (8)
- fonts.googleapis.com×4
- cdn.cookielaw.org×2
- fonts.gstatic.com×2
- c.la11-core1.sfdc-8tgtt5.salesforceliveagent.com×1
- cdn.userway.org×1
- cloud.typography.com×1
- web8.secureinternetbank.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 1995-08-17
- Expires
- 2028-08-16 820 days left
- Updated
- 2025-08-06
- Name servers
-
- ns1-57.akam.net
- ns4-65.akam.net
- ns5-65.akam.net
- ns7-65.akam.net
DNS records live
- NS
-
- ns1-57.akam.net
- ns4-65.akam.net
- ns5-65.akam.net
- ns7-65.akam.net
- MX
-
- 10 mxa-00103102.gslb.pphosted.com
- 10 mxb-00103102.gslb.pphosted.com
- TXT
-
Show 17 TXT records
google-site-verification=GFy6LjWovNp3Dd-toK5X9pIYpT4fRR3_kvZPU7j-aPsonetrust-domain-verification=6df073563ec44bcdbeb666f3fb79fc3capple-domain-verification=fEkGBxGbKiRcifXMamazonses:1bUi1m8tTePq0Nr8V81ZiPcmkpP1P2Ymq7OknY9k1B0=atlassian-domain-verification=ZO0VC2Ullbmlku1aXmJWWZT4hlj7pRRlaxHpcsP02oE1w/2UIsk1cJ3cgsnaBdLepaloaltonetworks-site-verification=f2ed3148c6c83688ab854966f471da8420c6457346c9a363e989417d7e524e32Dynatrace-site-verification=ffec0e35-79dc-475f-8389-5ffb3c40ee56__drhl9iksn2436fr5arghk4pv7tdocusign=49bdb12a-eb80-4ee5-81cb-baa86da38c37AP01m/p5O2POsKLnCwlB2T/t41EjNOCt0Scg+rT6uNTsLMSC6aXP9EQ967DX8kLZwJzXjGEhJjHtbUgIbgsr0A==docusign=822db81f-a14f-46a5-8a83-5ce2029c9e33MS=ms32584254.smartsheet-site-validation=EiDEIoDCVv1v8KiHgIJ8x-hu1ZEwEKr_citrix.mobile.ads.otp=ur0z1cbx4hlfp9kv9jgk2y3docker-verification=cc096bb2-d0f3-433d-a666-c4a6b5c69fd2_m7mvflr98a9akidn0ffy8n3oiycyjufadobe-idp-site-verification=127bccc97f69c9d734ae05abea7f658ebd10741d5be6a2541bec42b2a5b85ebcciscocidomainverification=593974c3b029d16c46af27198d6fa56174830e862cd5d87652973e5e1be0cec8
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCSY4dcrJrusVaMzRugUoll4LW4HymPPjb44cZiI2hKolNwMYiu32hBozIGqu68oEhyoxNAlP5L35Fo1LWR6h… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA08gigEfkwWasgeMOVUSV28PTJel0re/ac0FgwW9fp3ZD5RTFU8GKcb0YObCghnxyY1/Bfhu8Dglb9Qc5mo… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC943wdNTxSSgkHMtcayInS/vAJbEzpvTSXXfAQksiHqy9dbIW32N6zxjmTtOx8CP+UEmyzsghYHVA3SeXPrOwXws…
selectors probed - selector1:
Certificate (current)
DigiCert EV RSA CA G2
Expires in 10 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval'; img-src * 'unsafe-inline' 'unsafe-eval' 'self' data: https:; report-uri /report-csp-violation- strict-transport-security
max-age=31536000; includeSubdomains; preload