appsheet.com
HTML metadata
Technology
- Server
- sffe
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- www.gstatic.com×37
- fonts.googleapis.com×3
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 2010-06-03
- Expires
- 2027-06-03 380 days left
- Updated
- 2026-05-02
- Name servers
-
- ns-cloud-b1.googledomains.com
- ns-cloud-b2.googledomains.com
- ns-cloud-b3.googledomains.com
- ns-cloud-b4.googledomains.com
DNS records live
- NS
-
- ns-cloud-b1.googledomains.com
- ns-cloud-b2.googledomains.com
- ns-cloud-b3.googledomains.com
- ns-cloud-b4.googledomains.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=MzOFegbr4A07N1ea-LH3yAxgjkBi27jpjJJJJ93rHq0google-site-verification=IvPchr6sczl6kctPsQoFJ2Ns-64NzNcyC0s1KVwNAps
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:mailauth-reports@google.compolicy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAiSy/N5PHue8tLzUE8GV+iwr3sFbCeaeuDuocx3PjJ9DHMoO211CmbfwYKoO2af9hzzv84wVQ40MO+L…
selectors probed - google:
Certificate (current)
WR3
Expires in 55 days
HTTP security headers
- present
-
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src * blob: data:; script-src 'report-sample' https://www.google-analytics.com/analytics.js https://www.googletagmanager.com https://www.gstatic.com/glue/cookienotificationbar/cookienotificationbar.min.js https://www.gstatic.com/marketing-cms/reviewed-scripts/; object-src 'none'; style-src 'unsafe-inline' *; report-uri https://csp.withgoogle.com/csp/corp-marketing-cms-team; base-uri 'self'- cross-origin-opener-policy
same-origin; report-to="uxe-owners-acl/about_appsheet_com"- cross-origin-resource-policy
cross-origin- content-security-policy-report-only
require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/about_appsheet_com