calligo.io
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Hotjar
- Plausible
- Fonts
-
- Google Fonts
Third-party hosts loaded (12)
- ajax.googleapis.com×2
- fonts.googleapis.com×2
- static.addtoany.com×2
- www.googletagmanager.com×2
- cdn.jsdelivr.net×1
- cookiehub.net×1
- edge.marker.io×1
- js.hs-analytics.net×1
- plausible.io×1
- script.hotjar.com×1
- secure.smart-business-365.com×1
- static.hotjar.com×1
DNS records live
- NS
-
- audrey.ns.cloudflare.com
- rocco.ns.cloudflare.com
- MX
-
- 5 calligo-io.mail.protection.outlook.com
- TXT
-
Show 16 TXT records
ppe-58e3d34d7920651201a3c27817e27e33a191424dbj2jek8jrqqbvgsh6e6b1pcu43slack-domain-verification=isoDR8bjyvhawzgyM2eCZfSv7nfVkAj5XPKHwuPbsophos-domain-verification=05a9b9f0b4e2a67df443b4b2125fcea0b307f85a7c6ec974d33ecfe431bb4354760fc710-9642-4c8c-985d-cb00f433be9capple-domain-verification=ryxDRZYiwEFBIgG6jamf-site-verification=RkM9R3EbC3-d67Y9nZSqdwgoogle-site-verification=vAIlBN-gDEG1EhJHLCMK4vl7soFy13nnU0eMBy32nFcgoogle-site-verification=DvDD4gBvM_lzxZum4raR4seVCeLJ37lj-__1ebVRNZg1password-site-verification=BUEY7MEPGJF3FAGS62455PKUAAfd44b625779d4b1d915b8ce45e998d7554a087f582ca4dde91637aab6df0e4fagoogle-site-verification=KXleFP2BkBEYwUniHl-mN_59I_Kxzs9ayUizavnEudUdocusign=e59a2a39-43b4-4c48-8143-cc324f95557ec3e43342-eb71-4272-ad1d-ba78c7d31e6dgoogle-site-verification=QyFXktZQY1jJAZsc8mYZs8XO_dEe_WulKPXlihag2Ag
Email authentication strong
- SPF
-
v=spf1 include:_spf-eu.ppe-hosted.com include:servers.mcsv.net include:spf.protection.outlook.com include:2889618.spf04.hubspotemail.net include:spf.uk.exclaimer.net ip4:95.131.158.164 ip4:173.255.144.231 ip4:79.98.163.81 ip4:193.17.38.60 ip4:46.175.52.203 include:azure.quotevalet.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_report@calligo.cloud; ruf=mailto:dmarc_report@calligo.cloud; fo=1policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyE2ataYOjzYbag64geKFl3OlmLIYG6AkHIXNFKf5RNSUT8TDDpA+RAKP5iq+hWrxDcsbQkLDIWJ/1W… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 71 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' abs.twimg.com/responsive-web/ *.googleapis.com *.facebook.net *.mapbox.com cookiehub.net *.marker.io *.hs-scripts.com *.hs-analytics.net *.hs-banner.com *.hsadspixel.net/fb.js *.hscollectedforms.net *.hsforms.net *.hsleadflows.net *.usemessages.com plausible.io *.hotjar.com *.smart-business-365.com *.addtoany.com *.google-analytics.com/analytics.js *.googletagmanager.com *.gstatic.com *.licdn.com *.doubleclick.net *.google.com/recaptcha/ *.tableau.com *.jsdelivr.net; style-src 'report-sample' 'self' 'unsafe-inline' *.cookiehub.eu fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.mapbox.com *.hubapi.com *.marker.io *.x.com *.hotjar.io *.hsforms.com *.hubspot.com plausible.io *.linkedin.com *.google.com *.addtoany.com *.google-analytics.com wss://ws.hotjar.com *.hscollectedforms.net *.googleadservices.com *.doubleclick.net; font-src 'self' *.twimg.com fonts.gstatic.com data:;- strict-transport-security
max-age=2592000