cantina.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- external.cdn.signal.is×1
- optimized-img.cdn.signal.is×1
- s3.amazonaws.com×1
- www.googletagmanager.com×1
Contact
Registration
- Registrar
- NameCheap, Inc.
- Created
- 1998-11-20
- Expires
- 2026-11-19 183 days left
- Updated
- 2025-10-20
- Name servers
-
- ns-1091.awsdns-08.org
- ns-1544.awsdns-01.co.uk
- ns-248.awsdns-31.com
- ns-760.awsdns-31.net
DNS records live
- NS
-
- ns-1091.awsdns-08.org
- ns-1544.awsdns-01.co.uk
- ns-248.awsdns-31.com
- ns-760.awsdns-31.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 9 TXT records
google-site-verification=xebp28NuH0bfJYF0KFMD8Wfe891TdbZ7IQDhP8TZvgAproxy-ssl.webflow.comtiktok-developers-site-verification=RcnZvYvR3cRH8vdBJH6V8mqMQkhDqArzanthropic-domain-verification-nr9n0e=YvaqTLZZUXz8p3DuVMtVhHQ5Bapple-domain-verification=1MDSglqKOx8KM1atatlassian-sending-domain-verification=e39f20b4-a19d-47c5-9c03-f048e8e9ba83facebook-domain-verification=ij6uwzeel25iazqlxfv1kuda2eh86hglobalsign-domain-verification=HDQm_BzF1Dmu_bArfntY00jxUKPeAMRzZ2WQ3niMPDgoogle-site-verification=nnLABkHh2LHxq2Z1k7B7baMhy82QsKaORYWiaVJHlaQ
Email authentication strong
- SPF
-
v=spf1 include:mail.zendesk.com include:_spf.google.com include:_spf.atlassian.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@cantina.compolicy: quarantine - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAr82Slvk00nsawLEao6ShSgqv0rWyrjJ8xOcDUHCb6g9crTcNQNUkGpthHumc+SVTWkedx4q2y9skiQM… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0QsrEF221uAZhxHvQouVNtoJyDoXvv3PR3j1dJxX6q1uxDLTC/yndHKfy+p+tGdaxMYwEszmbokz/sJXUm… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnDZkep6/belNUHCDPd5oHYsBmXdSVBxdxd/BCNsXLxnMW1ZnOM+sxCgcFaSleU1PQQilfuSWFqEWYMe3op…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 150 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; connect-src 'self' blob: data: https://*.cloudfront.net https://*.amplitude.com https://*.amazonaws.com https://deathstar.signal.is https://deathstar-staging.signal.is https://www.google.com https://*.mixpanel.com https://cantina.com https://*.cantina.com wss://cantina.com wss://*.cantina.com wss://*.cantina.com:* https://*.signal.is https://*.cdn.signal.is wss://*.signal.is https://*.google-analytics.com https://api2.amplitude.com https://sdk.iad-05.braze.com https://fpjscdn.net https://api.fpjs.io https://*.sanity.io https://*.img.ly https://*.bugsnag.com https://cdn.plyr.io https://noembed.com https://vimeo.com https://api.vimeo.com https://widget.usersnap.com; default-src 'self'; font-src 'self' https://use.fontawesome.com https://*.img.ly/ https://fonts.gstatic.com data:; form-action 'self'; frame-ancestors 'none'; frame-src 'self' https://www.googletagmanager.com https://www.youtube.com https://www.google.com https://player.vimeo.com; img-src 'self' data: blob: h- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin