bloomfire.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (11)
- secure.innovation-perceptive52.com×3
- player.vimeo.com×2
- scripts.webeo.com×2
- gmpg.org×1
- js.hs-analytics.net×1
- js.hs-banner.com×1
- js.hs-scripts.com×1
- js.hsadspixel.net×1
- js.hubspot.com×1
- webeo-web-content.s3-eu-west-1.amazonaws.com×1
- www.googletagmanager.com×1
Social
Contact
- Address
- 1717 W 6th St, 78703, Austin, Texas, US
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2009-08-31
- Expires
- 2027-08-31 468 days left
- Updated
- 2025-08-06
- Name servers
-
- ns-1392.awsdns-46.org
- ns-1652.awsdns-14.co.uk
- ns-248.awsdns-31.com
- ns-916.awsdns-50.net
DNS records live
- NS
-
- ns-1392.awsdns-46.org
- ns-1652.awsdns-14.co.uk
- ns-248.awsdns-31.com
- ns-916.awsdns-50.net
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 30 alt2.aspmx.l.google.com
- 40 aspmx2.googlemail.com
- 50 aspmx3.googlemail.com
- TXT
-
Show 11 TXT records
google-site-verification=UAGu0TMMfRyqonMHxZKKdR1LP_whcQCO-fF3A6xyUoggoogle-site-verification=VCCK90jkVfcz0yUuyNmJ4wSAFGRkdMFCxLufKca3HEUgoogle-site-verification=uLSWzrQ4kwq2y3wbWJWqwYMzh8up7Bk_ffnTrXcd668MS=ms41440474atlassian-domain-verification=SaOYmid6BSNYKapyBj1EhGmRTFMK9lLozp2ZKToKnaJhJLnYm4OnKpbBinXSRu38ca3-4abec7b6a00a4727bc6f601222098298docusign=30394e11-ea55-4723-a11a-df0412adb9a8google-site-verification=4W6TLVP4qbw4_0KhFv8rn3Ejpw5H3V9AIxpVAxAWOlIgoogle-site-verification=Ervzs8tdZmQr4npHulfqWi1B4BtEiCNcUN0tgIiGBRcgoogle-site-verification=Ph4hH_Re9xeuvBbiaVAd2k_R52Ulkt7duGhyjeiJ19Ugoogle-site-verification=TBzkevaM1LHck_RfxP0NuOWUfveW-hN0Ii3zcraiWCQ
Email authentication strong
- SPF
-
v=spf1 a include:sendgrid.net include:_spf.google.com include:mailgun.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; sp=none; rua=mailto:ops+dmarc@bloomfire.com; ruf=mailto:ops+dmarc@bloomfire.com; pct=0; fo=1policy: reject (enforced) · pct=0 · sp=none - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApUU3XztM3vWuAhZEykdllj8UOlVXYY6LwaZ/3u83YfoOHBnmGAoiktXe95/vKW9HQxQGLLyQbK8BgQ… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwxJUyybfp+lKpBqVAQIIO9vrPSLhbPP+jes7C+aon+RUzV5frCakuAGxVO0bM1mrV5FPLhYGvc3FEmtIOs… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDhaAEGuLPSz1QXZZUImm/qKJLEinYV5OxzCMKDUiAAF9mV943w/KuM1Vp90wDFPeacYOZ2BwMzVsYz6NOBMLIrC7… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - google:
Certificate (current)
R13
Expires in 55 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
style-src 'self' 'unsafe-inline' https: data: ; script-src 'self' https: blob: data: 'unsafe-inline' 'unsafe-eval' ; img-src 'self' data: blob: https: ; font-src 'self' https: data: ; media-src 'self' http: blob: ; connect-src 'self' wss: https: blob: ; object-src 'self' blob:; frame-src 'self' *.vimeo.com https: ;- strict-transport-security
max-age=31536000; includeSubDomains; preload