y12fcu.org
HTML metadata
Technology
- Server
- Sucuri
- jQuery
- 3.4.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (12)
- integration.silvercloudinc.com×2
- www.googletagmanager.com×2
- ajax.googleapis.com×1
- api.alpharank.io×1
- cookie-cdn.cookiepro.com×1
- d21y75miwcfqoq.cloudfront.net×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- kaigentic-prod.kitsys.net×1
- kit.fontawesome.com×1
- resources.digital-cloud-west.medallia.com×1
- www.creditunionmatch.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1995-11-02
- Expires
- 2032-11-01 2356 days left
- Updated
- 2024-07-04
- Name servers
-
- bella.ns.cloudflare.com
- jim.ns.cloudflare.com
DNS records live
- NS
-
- bella.ns.cloudflare.com
- jim.ns.cloudflare.com
- MX
-
- 10 mxa-00543e01.gslb.pphosted.com
- 10 mxb-00543e01.gslb.pphosted.com
- TXT
-
MS=01877720808CAE1AD9DCE4B584DE4E57587BFD7Damazonses:2rlDvXaxRl7V8Ny4X4NpxTot4IGRCjSZCMxwUw5bYUo
- Verified for
-
- Cisco
- DocuSign
- Meta
- Microsoft 365
- OpenAI
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;policy: reject (enforced) - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVS9MJ04nptmREKLtpobYpQCzU7nInD782IulHwF0LSXnXQDw8Ykh/CUFcmcF+yk3r5ZGP3mN3hNtaqMaIjK… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDocsJUEZn20Yy9lVBTSEyA6yMK/TlGbKMv2YRd+uFnFGYqtKgQIwYhXZsRyp34c/8PLJGD1YNWPac3lK7W3t… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwSCdTooMjJQ81Spz8qsFk1MmwXjowE3be0vbiWflLEs0dEWBqNSkoh0NeKkVecIZ7m35fT7zjB/SOTzk7E… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIl1lero/TZuPuWRMp3VJCFfYx/ZL97QRjAU4rnKvs1YsvKGDKZNCGk13xa9tRw88f9hPN7NP4ZRt+48wJC/W3c4…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 54 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
frame-ancestors https://cors-test.codehappy.dev http://cms.y12fcu.org https://staging-cms.y12fcu.org https://psa.digitalinsight.com https://digital.y12fcu.org https://staging.y12fcu.org https://www.cusgcms.com http://y12fcu.org https://uat-internetloanapplication.cudl.com https://internetloanapplication.cudl.com http://y12cms.inetsolution.dev http://inetsolution.dev