albert.io
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- a-us.storyblok.com×5
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns-1405.awsdns-47.org
- ns-156.awsdns-19.com
- ns-1765.awsdns-28.co.uk
- ns-759.awsdns-30.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
google-site-verification=SXrwYxkQbng3-QoH2Li954nfqkK1_6brdp2tMM6NJDsgoogle-site-verification=U05jLtMzjGwdOdmyGMtvfoL9XFPtCBHUfr_r45TrEjogoogle-site-verification=ipJZmGJjZhjJxp7iqPxLKyTDmQlQPCGYSCStWk3RXxcgoogle-site-verification=v4cRZaaMp5CWfErjVxToXwcdvowKADxOBRSMoyuGrP0MS=08CE74EB6FD26C3F1078358D32657B440617CD3Bgoogle-site-verification=96Y_jp1h2skn90F6Ckycf0lp2oi0McWbG76bPIqtASs
Email authentication partial
- SPF
-
v=spf1 include:amazonses.com include:_spf.google.com include:_spf.createsend.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=none;rua=mailto:engineering+dmarcrua@albert.io;ruf=mailto:engineering+dmarcruf@albert.io;fo=1;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCBjl6Ecsv2Oa0hje3tG7bl8+7WlnlbyizBCTAvofnFxwlG6gNAQ8fNqaO7uGR6RtF28oYjCYrZauXJv1JRTl… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqQV7DxuV5JbQZCPZTraNQHBOWuQFgJEMP+ql2Lv3sd9lMUm+f+FanMY+tKBwGAeHt75VQRjKfk/77UWb+v… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjKunhLkCk4Evo7FvSt/8x6QPt69E6YqtVsxB+nZiRfq7lwhmHuM8EfgAxk/MpD3aLFzxZNUJ7F4X4do3xLs6hxJ…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 271 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' *.instructure.com https://app.storyblok.com https://webforms.pipedrive.com https://cdn.lemcal.com;- strict-transport-security
max-age=31536000