blmecapital.com
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (1)
- use.typekit.net×1
Social
Contact
- Phone
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2022-08-23
- Expires
- 2027-08-23 460 days left
- Updated
- 2026-05-16
- Name servers
-
- ns-1077.awsdns-06.org
- ns-1875.awsdns-42.co.uk
- ns-252.awsdns-31.com
- ns-591.awsdns-09.net
DNS records live
- NS
-
- ns-1077.awsdns-06.org
- ns-1875.awsdns-42.co.uk
- ns-252.awsdns-31.com
- ns-591.awsdns-09.net
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwjfldnp+37vlvFH8kv4RwJ4Ca9b4QW/4YbffHb5hRknCSA4AixyrOPo34QSSo8JpqnNZUKYS0hw7mqInDn… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDuMkNyo1egJnqzFWBMlP6tkp3iEIPZQfyxh5op1fTQeXehUluRBbxjrkQqVXcv3/hs1VEjI1ypJ/ok2ACiOxLpyi…
selectors probed - s1:
Certificate (current)
R13
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' data: https://blmeksa-production.s3.amazonaws.com https://blmeksa-staging.s3.amazonaws.com *.backend-api.io *.googletagmanager.com *.google-analytics.com *.googleapis.com *.gstatic.com *.typekit.net *.youtube.com *.vimeo.com https://vercel.live https://vercel.com https://*.pusher.com wss://*.pusher.com; frame-src *;- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (4)
- blme.com×1
- facebook.com×1
- linkedin.com×1
- twitter.com×1
Linked from (1)
- blme.com×1