career.io
HTML metadata
Technology
- CDN
- Amazon CloudFront
Third-party hosts loaded (1)
- images.ctfassets.net×68
Social
DNS records live
- NS
-
- ns-1515.awsdns-61.org
- ns-1720.awsdns-23.co.uk
- ns-495.awsdns-61.com
- ns-773.awsdns-32.net
- MX
-
Show 7 MX records
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 10 mx1.improvmx.com
- 20 mx2.improvmx.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 13 TXT records
anthropic-domain-verification-85zmzf=DY1vIpec9m7IWWGWYY1R3vCXMapple-domain-verification=OKXzsLzcChC07AcYatlassian-domain-verification=dHGonyaPY7LnisIdISUCVQaIMX09mqiMmwkeVt8k3mjbz0dbB4UhOv4wO4LKQqvqgoogle-site-verification=1Bnk-AYsBtKlguM9uQ7g_8OxnI5lUi49sQkJs-kiSLkgoogle-site-verification=vIi0mlgK8BOsWhuveJTz8DlrjaYSv3yrJ5MBGydl1VMknowbe4-site-verification=2f6bb185960d069be43eb7a5a6be2f0amiro-verification=79b6ea22f99882a4c23f438ee1b6b20cad492bd2mixpanel-domain-verify=8fcc8828-0991-49da-a052-ccb283b6c5eaopenai-domain-verification=dv-H3qIrAzFAopNaxWz6KOSGXXTMS=ms37797629MS=ms52016040ZOOM_verify_QzuJI4Sg7NTsnbqyE2lgErZOOM_verify_eDRhYSaz7ols853hKyNg6K
Email authentication partial
- SPF
-
v=spf1 a mx ip4:168.245.65.255 ip4:168.245.115.120 include:sendgrid.net include:spf.improvmx.com include:_spf.google.com include:spf.mailjet.com include:21170961.spf03.hubspotemail.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; sp=none; pct=100; ri=86400; rua=mailto:info@career.io; ruf=mailto:info@career.io; aspf=s; adkim=s; fo=1policy: none (monitoring only) · sp=none - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzT/a8rLgo/8vs9T9YGhwDOoa1R/PLwMKidDO7qN47HMyWX2ITlTsmaITaxx2s6MOd4iwU/WHsNxLBZfKRD… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBcMC0Q8/t6Szr3JePX7SDY4mENKy9YRXAZp6vk7u+VW8ucUw6WxFN6OTR51MbxPqpGxU/18ZtmyDzLsmEAJ1hZ3…
selectors probed - s1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 136 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; script-src 'self' 'strict-dynamic' 'nonce-0HdzHXdy4DQhb8P34akj1g==' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://images.ctfassets.net https://*.google-analytics.com https://*.googletagmanager.com https://obseu.ofgreencolumn.com https://bat.bing.com; media-src 'self' https://videos.ctfassets.net http://videos.ctfassets.net https://www.dropbox.com https://*.dropboxusercontent.com; font-src 'self'; connect-src 'self' https://cdn.contentful.com https://preview.contentful.com https://*.google-analytics.com https://*.analytics.google.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://bat.bing.com https://*.clarity.ms https://*.hotjar.io https://*.ingest.us.sentry.io https://api.resumatorapi.com https://obseu.ofgreencolumn.com/mon; frame-src 'self' https://www.googletagmanager.com https://*- strict-transport-security
max-age=31536000; includeSubDomains; preload