bloomeo.app

.app crawl

First seen 2026-04-13 · Last seen 2026-05-20 · ok HTTP/1.1 200 554 ms crawled 2026-05-07

US · 216.150.1.1 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Bloomeo: Master Your Budget & Achieve Early Retirement
Description
Transform your finances with Bloomeo! Track savings, set personalized budgets, and plan for early retirement. Start your journey to financial freedom today!
Language
en
Canonical
https://bloomeo.app

Open Graph

url
https://bloomeo.app
title
Bloomeo: Master Your Budget & Achieve Early Retirement
description
Transform your finances with Bloomeo! Track savings, set personalized budgets, and plan for early retirement. Start your journey to financial freedom today!

Technology

CDN
Vercel
CMS
Next.js

Third-party hosts loaded (2)

  • epkrbuzeqo5vc9dv.public.blob.vercel-storage.com×2
  • i.pravatar.cc×1

Contact

Email

DNS records live

NS
  • dns200.anycast.me
  • ns200.anycast.me
MX
  • 1 mx1.mail.ovh.net
  • 100 mx3.mail.ovh.net
  • 5 mx2.mail.ovh.net
TXT
  • firebase=bloomeo-1983d
Verified for
  • Brevo
  • Google

Email authentication strong

SPF
v=spf1 include:mx.ovh.com -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; pct=100; rua=mailto:contact@bloomeo.app;
policy: quarantine
DKIM
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificate (current)

R13
from 2026-05-04 to 2026-08-02
Expires in 73 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://bloomeo.app/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
Header values
referrer-policy
strict-origin-when-cross-origin
permissions-policy
camera=(), microphone=(), geolocation=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://datafa.st https://www.google.com https://www.gstatic.com https://client.crisp.chat; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://client.crisp.chat; img-src 'self' data: https: blob:; font-src 'self' data: https://fonts.gstatic.com https://client.crisp.chat; connect-src 'self' https://www.google-analytics.com https://datafa.st https://www.google.com https://www.gstatic.com https://client.crisp.chat wss://client.relay.crisp.chat https://storage.crisp.chat https://*.ingest.sentry.io; frame-src 'self' https://www.google.com https://*.applaunchpage.com https://game.crisp.chat; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://*.applaunchpage.com; upgrade-insecure-requests
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (2)

Linked from (4)