yassprize.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (6)
- js.hs-scripts.com×2
- gmpg.org×1
- px.ads.linkedin.com×1
- use.typekit.net×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2022-03-06
- Expires
- 2027-03-06 290 days left
- Updated
- 2026-04-20
- Name servers
-
- fish.ns.cloudflare.com
- watson.ns.cloudflare.com
DNS records live
- NS
-
- fish.ns.cloudflare.com
- watson.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 include:dc-aa8e722993._spfm.yassprize.org include:email.hivebrite.com include:39644148.spf05.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAh4Z1yqQeqpORQeIz4hbu1da/y+nVmtxcTGKMGUarr0qcaziT8WI0vKJDYmMcpz00m8VUrLG5A6iq5M… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsYHTiKqEX90RuN/GfQYjNqHZM2Iu4gsF/zszivcx0zVdjBkwpG8eA/yil4hC3LttGnzQ+8A9AiHod8wooz… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4gImLFdpzqztyfc/5nosSysgaI76jwu3WnBa5AVkFTg9CJgOV15V42CcHRmY4s8adQmDIdEK/LWfTNMAkQ…
selectors probed - google:
Certificate (current)
WE1
Expires in 50 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://*.hubspot.com https://*.hs-scripts.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hscollectedforms.net https://*.hsforms.com https://*.hsforms.net https://*.tiktok.com https://*.licdn.com https://*.doubleclick.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://*.hubspot.com https://*.hsforms.net; img-src 'self' data: blob: https:; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://*.hubspot.com https://*.hsforms.net https://live-stop-for-education.pantheonsite.io; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://www.googletagmanager.com https://*.doubleclick.net https://www.google.com https://*.hubspot.com https://*.hsforms.com https://*.hscollecte- strict-transport-security
max-age=31536000; includeSubDomains