back40financial.com

.com crawl

First seen 2026-04-15 · Last seen 2026-05-07 · ok HTTP/1.1 200 736 ms crawled 2026-05-10

US · 66.33.22.66 · AS400940 Railway

Reputation 92/100 no dmarc policy

sector finance type homepage

HTML metadata

Title
Back40 Financial | Retirement Income Planning
Description
Back40 Financial helps pre-retirees and retirees build a complete retirement income plan — engineered income, purposeful portfolios, and tax-efficient strategies.
Language
en
Canonical
https://back40financial.com/

Open Graph

title
Back40 Financial | Retirement Income Planning
site name
Back40 Financial
description
Back40 Financial helps pre-retirees and retirees build a complete retirement income plan — engineered income, purposeful portfolios, and tax-efficient strategies.

Technology

Server
railway-edge
CMS
Gatsby

Registration

Registrar
Squarespace Domains II LLC
Created
2023-08-28
Expires
2026-08-28 100 days left
Updated
2026-04-13
Name servers
  • arnold.ns.cloudflare.com
  • lilyana.ns.cloudflare.com

DNS records live

NS
  • arnold.ns.cloudflare.com
  • lilyana.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • google-site-verification=wtR7pgaRJC503JVZTuBER1RjgffQ4shAODJhoZH5SSQ

Email authentication weak

SPF
v=spf1 include:_spf.google.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

E7
from 2026-04-13 to 2026-07-12
Expires in 54 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://back40financial.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
camera=(), geolocation=(), microphone=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: blob: https:; font-src 'self' data:; connect-src 'self' https: ws: wss:; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin-allow-popups

Linked from (1)