brojure.com
HTML metadata
Technology
- Server
- Heroku
- Fonts
-
- Google Fonts
- Social widgets
-
- LinkedIn Widget
Third-party hosts loaded (3)
- fonts.googleapis.com×11
- maps.googleapis.com×1
- platform.linkedin.com×1
Social
Contact
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2014-01-10
- Expires
- 2030-01-10 1332 days left
- Updated
- 2024-12-17
- Name servers
-
- joel.ns.cloudflare.com
- tina.ns.cloudflare.com
DNS records live
- NS
-
- joel.ns.cloudflare.com
- tina.ns.cloudflare.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
Show 5 TXT records
google-site-verification=lyOM4nJJfTHkF8zKFRAzGLxD_F3FvJXqvvuaRwJLfasALIAS for brojure.herokuapp.comgoogle-site-verification=25FwMeG4RRs8TwwjDPAqY2W6SaPkzdiqx5s15zz4ly4google-site-verification=6lTBQ3oQJ4gmaFMPeOL_3nq00gi4-qTovGZGBzBdRlwgoogle-site-verification=X8vfxmkvYYz99vXg6PD-Igjlgh3hsrurk7fUmbpgs_c
Email authentication weak
- SPF
-
v=spf1 a include:_spf.google.com include:spf.mail.intercom -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 72 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin, strict-origin-when-cross-origin, no-referrer, no-referrer-when-downgrade, same-origin, origin, strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src *; child-src * 'unsafe-inline' 'unsafe-eval'; connect-src 'unsafe-inline' 'unsafe-eval' *; font-src 'unsafe-inline' 'unsafe-eval' data: *; form-action 'unsafe-inline' 'unsafe-eval' *; frame-src 'unsafe-inline' 'unsafe-eval' *; img-src 'unsafe-inline' 'unsafe-eval' data: *; manifest-src * 'unsafe-inline' 'unsafe-eval'; media-src 'unsafe-inline' 'unsafe-eval' *; object-src 'unsafe-inline' 'unsafe-eval' *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline' 'unsafe-eval'- strict-transport-security
max-age=631138519