autopay.io
HTML metadata
Technology
Third-party hosts loaded (1)
- cdn.ravenjs.com×1
DNS records live
- NS
-
- ns-cloud-a1.googledomains.com
- ns-cloud-a2.googledomains.com
- ns-cloud-a3.googledomains.com
- ns-cloud-a4.googledomains.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 8 TXT records
firebase=autopay-prod-iofirebase=autopay-prod-bookingapple-domain-verification=MCji8KkIJAxJxDEQatlassian-domain-verification=97DZXaBt3aeCMXZZOSPHpt4bq8wrJaGag9qMGzGwaa3u0cI1LvAof9S9eBURBaaav=spf1 include:spf.mailjet.com include:mail.zendesk.com include:_spf.google.com ~allgoogle-site-verification=BUzD54xyavO7a2QflWdSxfXQe6t-wHOjNfNZ0wh-eXAMS=ms76871669google-site-verification=aTBOn9AqDk4YfLq9CFqi5uSbTucg6hSeTb02lcmVBZs
Certificate (current)
WR3
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin- x-frame-options
deny- x-content-type-options
nosniff- content-security-policy
default-src 'none'; media-src 'self'; frame-src 'self' https://*.autopay.io https://stonly.com https://*.stonly.com https://player.vimeo.com *.europe-west1.firebasedatabase.app https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; script-src 'self' *.europe-west1.firebasedatabase.app cdn.ravenjs.com www.google-analytics.com apis.google.com stonly.com https://player.vimeo.com https://plausible.io 'sha256-fwc0mpDa8OHTVGvj46tzJTK/4veec5TxZJQNTFjzBw0=' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; connect-src 'self' *.autopay.io *.googleapis.com *.google-analytics.com *.europe-west1.firebasedatabase.app wss://*.europe-west1.firebasedatabase.app sentry.io https://vimeo.com api.pwnedpasswords.com stonly.com *.stonly.com https://plausible.io; img-src 'self' https://storage.googleapis.com/autopay-test-api.appspot.com/ https://storage.googleapis.com/autopay-qa-api.appspot.com/ https://storage.googleapis.com/autopay-prod-api.appspot.com/ https://*.aut- strict-transport-security
max-age=31556926; includeSubDomains; preload- content-security-policy-report-only
default-src 'none'; media-src 'self'; frame-src 'self' https://*.autopay.io https://stonly.com https://*.stonly.com https://player.vimeo.com *.europe-west1.firebasedatabase.app https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; script-src 'self' *.europe-west1.firebasedatabase.app cdn.ravenjs.com www.google-analytics.com apis.google.com stonly.com https://player.vimeo.com https://plausible.io 'sha256-fwc0mpDa8OHTVGvj46tzJTK/4veec5TxZJQNTFjzBw0=' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ 'unsafe-eval'; connect-src 'self' *.autopay.io *.googleapis.com *.google-analytics.com *.europe-west1.firebasedatabase.app wss://*.europe-west1.firebasedatabase.app sentry.io https://vimeo.com api.pwnedpasswords.com stonly.com *.stonly.com https://plausible.io; img-src 'self' https://storage.googleapis.com/autopay-test-api.appspot.com/ https://storage.googleapis.com/autopay-qa-api.appspot.com/ https://storage.googleapis.com/autopay-prod-api.appspot.com/