workplace.com
HTML metadata
Technology
Third-party hosts loaded (1)
- static.xx.fbcdn.net×31
Social
Contact
Registration
- Registrar
- RegistrarSEC LLC
- Created
- 1997-06-02
- Expires
- 2035-06-01 3299 days left
- Updated
- 2025-09-03
- Name servers
-
- a.ns.facebook.com
- b.ns.facebook.com
- c.ns.facebook.com
- d.ns.facebook.com
DNS records live
- NS
-
- a.ns.facebook.com
- b.ns.facebook.com
- c.ns.facebook.com
- d.ns.facebook.com
- TXT
-
Show 7 TXT records
google-site-verification=m9Pb1UhCxUbekCpI9JMyI8tTQLYhGU77aL6rpifWWkMgoogle-site-verification=3-Tb9QmBeR88hd2afYYYOyl2jKbN42w8UdoSGUN2SUczoom-domain-verification=4b2ef4e1-6dee-4483-9869-9bef353fd147google-site-verification=zH46qRHLRAQhZap1IA8h5TJLmTCYlm1EpZFjVRVSbmUgoogle-site-verification=nNYVlFDJZnVveUKA3qZ9ZeFzzxGZNbK0is6Ppb117UMc6a85e6e954b4624aac3aa82fa1b6544facebook-domain-verification=rnzvqz75hh7320s8p4cr3sbckt70tw
Email authentication no MX
- SPF
-
v=spf1 a ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expired 5 days ago
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
Header values
- permissions-policy
accelerometer=(), attribution-reporting=(), autoplay=(), bluetooth=(), camera=(), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(), clipboard-write=(), compute-pressure=(), display-capture=(), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(), gyroscope=(), hid=(), idle-detection=(), interest-cohort=(), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), otp-credentials=(), payment=(), picture-in-picture=(), private-state-token-issuance=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=();report-to="permissions_policy"- x-content-type-options
nosniff- content-security-policy
frame-ancestors https://*.workplace.com https://workplace.com;, default-src blob: workplace.com *.workplace.com facebook.com *.facebook.com fbthirdpartypixel.com *.fbthirdpartypixel.com fbcdn.net *.fbcdn.net fbsbx.com *.fbsbx.com cdninstagram.com *.cdninstagram.com instagram.com *.instagram.com internalfb.com *.internalfb.com oculuscdn.com *.oculuscdn.com whatsapp.net *.whatsapp.net workplace.tools *.workplace.tools;script-src *.workplace.com workplace.com *.facebook.com *.fbcdn.net 'nonce-wE66QLPu' blob: 'self';style-src data: blob: 'unsafe-inline' workplace.com *.workplace.com facebook.com *.facebook.com fbthirdpartypixel.com *.fbthirdpartypixel.com fbcdn.net *.fbcdn.net fbsbx.com *.fbsbx.com cdninstagram.com *.cdninstagram.com instagram.com *.instagram.com internalfb.com *.internalfb.com oculuscdn.com *.oculuscdn.com whatsapp.net *.whatsapp.net workplace.tools *.workplace.tools;connect-src *.workplace.com workplace.com *.facebook.com facebook.com *.fbcdn.net wss://*.facebook.com:* w- strict-transport-security
max-age=31536000; preload; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-resource-policy
same-origin