westcountyservices.org
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×3
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns09.domaincontrol.com
- ns10.domaincontrol.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 30 alt2.aspmx.l.google.com
- 40 aspmx2.googlemail.com
- 50 aspmx3.googlemail.com
- Verified for
-
- Zoom
Email authentication partial
- SPF
-
v=spf1 include:_spf.westcountyservices_org._d.easydmarc.pro ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;rua=mailto:2ca406d8ff@rua.easydmarc.us;ruf=mailto:2ca406d8ff@ruf.easydmarc.us;fo=1;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzOnAykdEp7cbYvPRLMkBwoOlhEnWaRc6pRjHogTfAidTFF4p9h/pB08PcNnV/wHWanfjCMOqikIEDB… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - google:
Certificate (current)
R13
Expires in 45 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.gstatic.com *.googleapis.com *.google-analytics.com *.googletagmanager.com *.gravityforms.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; font-src 'self' fonts.gstatic.com; img-src 'self' data: *.googleapis.com *.gstatic.com *.google-analytics.com *.googletagmanager.com *.gravatar.com; frame-src 'self' *.google.com *.youtube.com; connect-src 'self' *.google-analytics.com *.googleapis.com;- strict-transport-security
max-age=63072000; includeSubDomains; preload