banqu.app
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- js.sentry-cdn.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns-1044.awsdns-02.org
- ns-1939.awsdns-50.co.uk
- ns-70.awsdns-08.com
- ns-870.awsdns-44.net
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 177 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
img-src 'self' data: blob: banqu-photos-prod.s3.amazonaws.com banqu-photos.s3.amazonaws.com banqu-photos.s3.us-west-2.amazonaws.com banqu.zendesk.com *.openstreetmap.org;script-src 'self' 'unsafe-inline' www.google-analytics.com www.googletagmanager.com https://browser.sentry-cdn.com https://js.sentry-cdn.com *.zdassets.com;connect-src 'self' banqu-photos-prod.s3.amazonaws.com *.google-analytics.com *.sentry.io *.zdassets.com fonts.gstatic.com fonts.googleapis.com banqu.zendesk.com;frame-src 'self' /reports;form-action 'self' banqu.zendesk.com;default-src 'self';base-uri 'self';font-src 'self' https: data:;frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'- strict-transport-security
max-age=15552000; includeSubDomains
Linked from (1)
- banqu.co×1