calicocloud.io
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×3
- fonts.gstatic.com×1
- widget.clym-sdk.net×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns-cloud-d1.googledomains.com
- ns-cloud-d2.googledomains.com
- ns-cloud-d3.googledomains.com
- ns-cloud-d4.googledomains.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
_4dg9gudj99m5lggt9ekxxiv5k0mztvcgoogle-site-verification=g9vl_NQxHoVE34ONiy_8bPH65beYdTI0SfYPl3B2QpQ
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:sendgrid.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:52kcthci@ag.us.dmarcian.com;policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArOUH5QdeeuF+31LFuOCoKaB/5BE9eQujXjWxy8g2lmOPqOCup+gZQg6GeMPoZqia+5FpU1WW2XJiDK…
selectors probed - google:
Certificate (current)
R12
Expires in 43 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- cross-origin-opener-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- content-security-policy
default-src 'none'; frame-ancestors 'none'; frame-src 'self' *.calicocloud.io *.tigera.io tigera.io *.clym-sdk.net *.candu.ai *.arcade.software; script-src 'self' 'nonce-cBbv8t_yZQed3OJeYuRyR5fUKkvUBSi6nKCEg1kCkFk=' *.tigera.io tigera.io www.googletagmanager.com www.googleoptimize.com api.candu.ai cdn.candu.ai *.clym-sdk.net *.arcade.software *.mxpnl.com *.mixpanel.com; connect-src 'self' *.calicocloud.io *.tigera.io tigera.io api.candu.ai cdn.candu.ai *.google-analytics.com *.mxpnl.com *.clym.io *.mixpanel.com; child-src 'self' blob:; worker-src 'self' blob:; img-src 'self' data: image/png *.tigera.io tigera.io *.wp.com *.gravatar.com *.googleusercontent.com *.githubusercontent.com www.googletagmanager.com images.candu.ai media.candulabs.com cdn.candu.ai cdn.auth0.com *.atlassian.net *.atl-paas.net; style-src 'self' 'unsafe-inline' *.tigera.io tigera.io cdn.candu.ai p.typekit.net fonts.googleapis.com fonts.gstatic.com use.typekit.net media.candulabs.com *.arcade.software; font-src 'se- cross-origin-opener-policy
same-origin