hogum
putnam.com

putnam.com security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

3risk

Low

Minor observations only.

0Critical
0High
0Medium
1Low
2Info
Collected 4.6sfrom cache
  1. Certificate Transparency
  2. DNS resolution2
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs26
  6. Registration
  7. DNS posture2
  8. Email authentication2
  9. Certificate
  10. Security headers3
  11. Archived URLs
  12. Analysis3
  • noteCertificate Transparency did not complete (HTTP 502). Results below are partial.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • note2 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://www.putnam.com/putnam-investmentsstatus 200time 358msstack cloudflare
  • http:// redirects to https://
  • Strict-Transport-Security
    max-age=15768000
  • Content-Security-Policy
    script-src 'self' 'unsafe-eval' 'unsafe-inline' *.adoberesources.net *.ads.linkedin.com *.apolloplatform.com *.brightcove.com *.brightcove.net *.clarity.ms *.de…
  • Clickjacking protection
    via CSP frame-ancestors
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Cookie TiPMix
    Secure · HttpOnly · SameSite=none
  • Cookie x-ms-routing-name
    Secure · HttpOnly · SameSite=none
  • Cookie __cf_bm
    Secure · HttpOnly · SameSite=none
  • Receives mail via 2 servers
  • !SPFends in ~all
    v=spf1 include:us._netblocks.mimecast.com include:spf.protection.outlook.com ~all
  • DMARCp=reject
    v=DMARC1; p=reject; rua=mailto:390ea5e05658911@rep.dmarcanalyzer.com; ruf=mailto:390ea5e05658911@for.dmarcanalyzer.com; fo=1;
  • !MTA-STSinbound mail can be downgraded to plaintext
  • Registered with CSC Corporate Domains, Inc.32.0 years old
  • Registration expiry364 days
    2027-09-06
  • Transfer lock
    client transfer prohibited, server delete prohibited, server transfer prohibited, server update prohibited
  • 2 nameservers at registry
AddressPortsCVEsEdgeNetwork
172.64.145.165
80443205220532082208320862087+5
0Cloudflare~
104.18.42.91
80443205220532082208320862087+5
0Cloudflare~
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.