acornfinance.com

.com crawl

First seen 2026-04-12 · Last seen 2026-05-18 · ok HTTP/1.1 200 1267 ms crawled 2026-05-06

US · 162.159.135.42 · AS13335 Cloudflare, Inc.

Reputation 97/100 dmarc monitor-only

Classifying

HTML metadata

Title
Acorn Finance: 100% Free Contractor Financing for Good & Bad Credit
Description
Acorn Finance helps contractors offer fast, affordable financing for customers with good & bad credit. Get quick approvals, competitive rates, and simple tools to grow your business.
Language
en-US
Canonical
https://www.acornfinance.com/

Open Graph

url
https://www.acornfinance.com/
title
Offer Easy Financing to Your Customers | Acorn Finance for Contractors
locale
en_US
site name
Acorn Finance
description
Boost sales and win more jobs by offering fast, affordable financing through Acorn Finance. Simple setup, instant offers, and no dealer fees.

Technology

CDN
Cloudflare
CMS
WordPress
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Contact

Email
Address
st a { color: #0092

Registration

Registrar
GoDaddy.com, LLC
Created
1999-06-28
Expires
2031-06-28 1866 days left
Updated
2026-04-22
Name servers
  • ns-1484.awsdns-57.org
  • ns-157.awsdns-19.com
  • ns-1752.awsdns-27.co.uk
  • ns-666.awsdns-19.net

DNS records live

NS
  • ns-1484.awsdns-57.org
  • ns-157.awsdns-19.com
  • ns-1752.awsdns-27.co.uk
  • ns-666.awsdns-19.net
MX
Show 7 MX records
  • 0 mx1-us1.ppe-hosted.com
  • 0 mx2-us1.ppe-hosted.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 100 aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 6 TXT records
  • google-site-verification=7Zl7sW6xK_ln4UbCJLlnI1U7zLDghPvM4UWFXa3qvog
  • google-site-verification=fLT_Wu3zAXQUS1lSL_F__WDp8T8T1vw-B8_G1R9utKI
  • miro-verification=7c9023fe3528af7a63540956d6b69e9a27176474
  • ppe-50d86d8e2f6793a85f46ddbe9ed259052e0247fb
  • anthropic-domain-verification-5fdrs3=roUQRSxtY19fETSIYgARilEoa
  • facebook-domain-verification=kd448pn3b57fcn02wvlhp9u79850o3

Email authentication strong

SPF
v=spf1 include:_spf-us.ppe-hosted.com include:_spf.google.com include:spf.mandrillapp.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAg5x2uqZG708wpkUn2aUqI2fQcbb1Qg5byByTW8mPyGRwK5E8zVpOd8Ti9CrjvO5G2JIaJ9jLPs9zqE…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
  • smtpapi: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed

Certificate (current)

WE1
from 2026-03-30 to 2026-06-28
Expires in 40 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.acornfinance.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
base-uri 'self'; default-src 'self' blob: https://*.acornfinance.com https://*.acornfinance.dev; manifest-src 'self'; upgrade-insecure-requests; worker-src 'self' blob:; child-src 'self' https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; form-action 'self' https://your.acornfinance.com https://*.your.acornfinance.com https://mg.blogvault.net https://intercom.help https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://forms.hsforms.com https://www.facebook.com; connect-src 'self' 'unsafe-inline' https://*.hubspot.com https://content.hotjar.io https://dev.visualwebsiteoptimizer.com https://sst.acornfinance.com https://via.intercom.io https://api.intercom.io https://api.au.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom
strict-transport-security
max-age=31536000; includeSubDomains

Links to (1)

Linked from (15)