working.com

.com crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 1486 ms crawled 2026-05-18

US · 34.111.67.160 · AS396982 Google LLC

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Job Search Canada | Find Your Next Job With Working.com
Language
en
Canonical
https://www.working.com/

Open Graph

url
https://www.working.com/
title
Job Search Canada | Find Your Next Job With Working.com
site name
Working.com

Technology

Server
nginx
Analytics
  • Google Tag Manager

Third-party hosts loaded (6)

  • storage.googleapis.com×3
  • cdn.jsdelivr.net×2
  • www.googletagmanager.com×2
  • 23dc09d6-b664-425a-a76e-0eed6a6cc102.edge.permutive.app×1
  • ajax.googleapis.com×1
  • b.scorecardresearch.com×1

Registration

Registrar
Webnames.ca Inc.
Created
1995-01-04
Expires
2027-01-03 228 days left
Updated
2026-04-16
Name servers
  • ns-cloud-b1.googledomains.com
  • ns-cloud-b2.googledomains.com
  • ns-cloud-b3.googledomains.com
  • ns-cloud-b4.googledomains.com

DNS records live

NS
  • ns-cloud-b1.googledomains.com
  • ns-cloud-b2.googledomains.com
  • ns-cloud-b3.googledomains.com
  • ns-cloud-b4.googledomains.com
MX
  • 10 mxa-00385001.gslb.pphosted.com
  • 10 mxb-00385001.gslb.pphosted.com
TXT
  • ms=ms81344600

Email authentication partial

SPF
v=spf1 include:spf-00385001.pphosted.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

WR3
from 2026-04-05 to 2026-07-04
Expires in 45 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.working.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
Header values
referrer-policy
no-referrer
x-frame-options
ALLOWALL
permissions-policy
geolocation=(*)
x-content-type-options
nosniff
content-security-policy
default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; frame-ancestors * data: blob: ;
strict-transport-security
max-age=2592000;

Linked from (4)