clade.co
HTML metadata
Technology
- CDN
- Cloudflare
DNS records live
- NS
-
- hope.ns.cloudflare.com
- noah.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 4 TXT records
hubspot-developer-verification=YjNiNDBkZWItNjIyNy00YzhkLThmMWItYzIwMTJhYmRlZmU1launchdarkly-domain-verification=dce4c829-137c-483e-b67c-4731de4627b8status-page-domain-verification=6b18r5k7t318zoom-domain-verification=ZOOM_verify_5871323b02b54d9b83b706702db4c93e
- Verified for
-
- 1Password
- Anthropic
- Microsoft 365
- Notion
- Stripe
- Twilio
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:stspg-customer.com include:sendgrid.net include:5524417.spf02.hubspotemail.net include:22466451.spf02.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=1; rua=mailto:93d0107b19bf474e8788036d310c22fa@dmarc-reports.cloudflare.net,mailto:dmarc-reports@clade.co; sp=none; aspf=r; adkim=r;policy: quarantine · pct=1 · sp=none - DKIM
-
Show 5 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyTXEZGtJabNyFsLWnxoBEtuoUHx5JM91nVWozs3tusYkMZiofnGhYoftHb4ff3yBM3FTDs1cXVyHkX… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDExC+wNVzo2H5gPuYcfgwp4ESDoNhfcUQUqUzriNzEvdYsnZlFTlS1yTejfCRETV14SElK+q2iqITzuKDJIpv8gPPmxgW… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuqf8+qBeGpK9XH5MVEvCcXAfP9WSs4gqegQKEWiwcidwRzka0LKtcNdNJNChO1mL+uw009FI7VcPpdKfxv… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDLrzJEgEXi0+zHQ0aRoQ+2oE2uzVfPN6AuFWBh31YExORIqYyNiVwo3MSnq5+Yhmjt5emLbJcjvpbzYSiT8Fl/mw… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - google:
Certificate (current)
WE1
Expires in 71 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; form-action 'self'- strict-transport-security
max-age=315360000; includeSubdomains; preload