brownleepress.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
Third-party hosts loaded (2)
- brownlee-medusa.s3.us-east-2.amazonaws.com×31
- s3.us-east-1.amazonaws.com×6
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2019-06-22
- Expires
- 2026-06-22 33 days left
- Updated
- 2026-04-20
- Name servers
-
- art.ns.cloudflare.com
- venus.ns.cloudflare.com
DNS records live
- NS
-
- art.ns.cloudflare.com
- venus.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
Email authentication weak
- SPF
- not published
- DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; font-src 'self' https://js.stripe.com; frame-src 'self' https://js.stripe.com https://hooks.stripe.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com; connect-src 'self' https://api.stripe.com https://js.stripe.com https://*.medusajs.app https://*.medusajs.site; img-src 'self' data: blob: https: http:; style-src 'self' 'unsafe-inline' https://js.stripe.com- strict-transport-security
max-age=86400; includeSubDomains; preload