compoundplanning.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
Third-party hosts loaded (3)
- forms.default.com×1
- static.cloudflareinsights.com×1
- www.googletagmanager.com×1
Contact
- Address
- st Growing RIAs” (awarded 7/11/25). Rankings are based on 2024
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2023-08-23
- Expires
- 2026-08-23 95 days left
- Updated
- 2025-07-19
- Name servers
-
- isla.ns.cloudflare.com
- norm.ns.cloudflare.com
DNS records live
- NS
-
- isla.ns.cloudflare.com
- norm.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 8 TXT records
rippling-domain-verification=adcd75c66236686aslack-domain-verification=S637X9iuQLuZ6r0XvPj9iycMFe1OcFmm33Lb0lxSMS=ms57107655SFMC-gbn8Gi59bizl1J7Yluz4uMO0EakNxsE1dJooJv0Iapple-domain-verification=ekdvZ33PY55GJUSCdocusign=24493db3-c386-4767-a0a1-49e640294447google-site-verification=_mE29kwJo80kGVtsdt7ObOa66AaRFK9EsXBw4lwGBCwgoogle-site-verification=or5NDV8CbtcBNPbvq1LKxRNbRjYGxCBfScjYtpLDV9A
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:_spf.salesforce.com include:amazonses.com include:21724310.spf02.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@compoundplanning.com; sp=none; aspf=r;policy: quarantine · sp=none - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnuJj2oR7AMlP44K+0HWqtZUTMyydFwbdhBPwQ46TvgOhzbz2b6irItgMtIdi/pe+BtmBUvDjo0eAqP… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsiAmYJ/FJD9UmVnLoQS4uiT1wL8MS4QeDpCDvIq5mZEUJfVgH1pKZX6CdE530lAr61OO1iNX+wmxorsPB3… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6yrM/0E3NkRXJZH60mcmaDveCY+t1CK/abcTLuzctNcLermRqa9ZNyTi/4YUHIBkdmJTTgBXb+DIG0U0jt3bdfa…
selectors probed - google:
Certificate (current)
WE1
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: https://*.compoundplanning.com; connect-src 'self' https://*.compoundplanning.com https://api.hubapi.com https://browser-intake-datadoghq.com https://cta-service-cms2.hubspot.com https://data.sequel.io https://distillery.wistia.com https://embed-cloudfront.wistia.com https://fast.wistia.com https://fast.wistia.net https://nucleus.default.com https://o1180762.ingest.us.sentry.io https://pipedream.wistia.com https://sr-client-cfg.amplitude.com https://us-assets.i.posthog.com https://us.i.posthog.com https://v8zt8kni.apicdn.sanity.io https://www.google.com https://*.google-analytics.com https://px.ads.linkedin.com https://*.googletagmanager.com https://*.googleadservices.com https://static.hsappstatic.net https://browser.sentry-cdn.com https://api.introvoke.com; script-src * 'self' 'unsafe-eval' 'unsafe-inline' blob:; style-src 'self' 'unsafe-inline' https://*.compoundplanning.com https://assets.calendly.com https://fast.wistia.com https://pixel-cdn.default.com; i- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (3)
- ashbyhq.com×2
- fa-mag.com×2
- forbes.com×2