capsule.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-08 · ok HTTP/1.1 200 2134 ms crawled 2026-05-08

US · 64.239.109.1 · AS16509 Amazon.com, Inc.

Reputation 100/100

sector health type homepage

HTML metadata

Title
Capsule | The smarter, simpler, kinder pharmacy
Description
Prescriptions delivered the same day. Your insurance accepted. Pharmacists who text. For free.
Language
en
Canonical
https://www.capsule.com/

Open Graph

title
Capsule | The smarter, simpler, kinder pharmacy

Technology

CDN
Vercel
CMS
Next.js
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • www.googletagmanager.com×2
  • assets.customer.io×1

Social

Contact

Email
Phone

Registration

Registrar
Squarespace Domains II LLC
Created
1999-03-10
Expires
2027-03-10 294 days left
Updated
2026-02-23
Name servers
  • ns-1468.awsdns-55.org
  • ns-1629.awsdns-11.co.uk
  • ns-165.awsdns-20.com
  • ns-551.awsdns-04.net

DNS records live

NS
  • ns-1468.awsdns-55.org
  • ns-1629.awsdns-11.co.uk
  • ns-165.awsdns-20.com
  • ns-551.awsdns-04.net
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 11 TXT records
  • google-site-verification=bNmIjsM9F6PpZlDgO4vV55OvjZXitoubTt945b2MVqY
  • parsec-domain-verification=td_2XwU04cFHvLCUDmbcIMgIHaHXrF
  • rippling-domain-verification=91fb2a354b059b7e
  • segment-site-verification=Mi1ENGlqMrbpSrwfze2fMm6RRLeVn3ss
  • Bt8uwJYSwCa4aFj8_aRnhmTPGe4
  • ZOOM_verify_k5MLGIXySlOusM9nvnStDw
  • asv=c8eaa2efc61b5570d670068f31da989f
  • atlassian-domain-verification=DimUnjatn8bpHLconhkaZHbO4WtsClDbVjFSkSwWXLi0XJazddWmcQnbWbd34OX7
  • cursor-domain-verification-6kfjnt=9mJEADNqZnbA33rlU8onBUGlo
  • dropbox-domain-verification=vwn1m8ypalhp
  • google-site-verification=5fq5-gkwS6yBZCBlo1RVU2FMGT_gu1LgdU8pj-wiM-I

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:customeriomail.com include:_spf.niceincontact.com ip4:205.201.128.0/20 ip4:198.2.128.0/18 IP4:148.105.0.0/16 ~all
softfail (~all)
DMARC
v=DMARC1;p=reject;sp=reject;pct=100;rua=mailto:spam-notifications@capsule.com
policy: reject (enforced) · sp=reject
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArQbr5SqhwwZYf8wDq2XGyrHGt27T23jePBUaV3KGY4FyRDXjFto9KmkEvuo7kQ0ZWPvMu3zekUU3B8…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0D2uIgIswnpco96S8EXHB9yWKdH8yU6Zz96MA2jLFNRFf/gYuOT4EkEvP/PuH5Sg7vIAKuVu+mGzX7whWw…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCm7o+rgO1hT8bfVF9iOhwOsmJJmLpITDeBOrjM0FJZeffZffTg2npxfeckUahf2T8RDAZgQTMzzd0RXY1o5JVzJT…
selectors probed

Certificate (current)

R13
from 2026-04-22 to 2026-07-21
Expires in 63 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.capsule.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
geolocation=(), microphone=(), camera=(), payment=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' blob: https://*.vercel.com/ https://*.vercel.live/ https://*.vercel.app/ https://*.vercel-insights.com/ https://www.googletagmanager.com https://*.optimizely.com https://*.segment.com https://*.segment.io https://vimeo.com https://player.vimeo.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.amplitude.com https://sentry.io https://*.sentry.io https://*.mapbox.com https://*.inspectlet.com http://api.amplitude.com https://js.stripe.com https://*.capsule.com https://*.clearrx.co https://*.capsulecares.com https://*.capsulerx.com https://hipaa.jotform.com https://*.hotjar.com https://production-capsule-assets.s3.amazonaws.com https://*.google.com https://*.doubleclick.net https://*.amazon-adsystem.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.vercel.com/ https://*.vercel.live/ https://*.vercel.app/ https://*.vercel-insights.com/ https://*.logrocket.io/ https://*.logrocket.com/ https://*.lr-ingest.io/ https://*.
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (5)

Linked from (1)