zfinstitutes.com

.com crawl

First seen 2026-05-15 · Last seen 2026-06-01 · ok HTTP/1.1 200 3367 ms crawled 2026-05-19

US · 72.167.210.241 · AS398101 GoDaddy.com, LLC

Reputation 87/100 weak security headers no dmarc policy

Classifying

HTML metadata

Title
Zakat Foundation Institute
Language
en-US
Generator
WordPress 6.9.4
Canonical
https://www.zfinstitutes.com/
Feeds

Technology

Server
Apache
CMS
WordPress 6.9.4
PHP
8.4.19
jQuery
3.7.1
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • www.googletagmanager.com×2
  • www.facebook.com×1

Social

Contact

Phone

Registration

Registrar
GoDaddy.com, LLC
Created
2023-11-06
Expires
2026-11-06 156 days left
Updated
2023-11-06
Name servers
  • ns49.domaincontrol.com
  • ns50.domaincontrol.com

DNS records live

NS
  • ns49.domaincontrol.com
  • ns50.domaincontrol.com
MX
  • 0 mail.zfinstitutes.com

Email authentication weak

SPF
v=spf1 a mx ptr include:secureserver.net ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R12
from 2026-04-03 to 2026-07-02
Expires in 30 days

HTTP security headers

Header hygiene 45/100 Checked live page: https://www.zfinstitutes.com/

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self'; script-src 'self' https://www.zfinstitutes.com https://zfinstitutes.com https://s.w.org https://stats.wp.com https://www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com https://ssl.google-analytics.com https://region1.google-analytics.com https://analytics.google.com https://www.google.com https://www.gstatic.com https://ssl.gstatic.com https://www.recaptcha.net https://recaptcha.net https://challenges.cloudflare.com https://js.stripe.com https://www.paypal.com https://sandbox.paypal.com https://www.sandbox.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://youtube-nocookie.com https://s.ytimg.com https://i.ytimg.com https://player.vimeo.com https://f.vimeocdn.com https://i.vimeocdn.com https://fonts.googleapis.com https://fonts.gstatic.com https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https:

Links to (9)

Linked from (50)