coticsy.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Ads
-
- Meta Pixel
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- images.unsplash.com×5
- connect.facebook.net×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- www.facebook.com×1
- www.googletagmanager.com×1
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2025-08-25
- Expires
- 2028-08-25 829 days left
- Updated
- 2025-08-25
- Name servers
-
- ns-1515.awsdns-61.org
- ns-1557.awsdns-02.co.uk
- ns-4.awsdns-00.com
- ns-593.awsdns-10.net
DNS records live
- NS
-
- ns-1515.awsdns-61.org
- ns-1557.awsdns-02.co.uk
- ns-4.awsdns-00.com
- ns-593.awsdns-10.net
- MX
-
- 10 mx.zoho.com
- 20 mx2.zoho.com
- 50 mx3.zoho.com
- TXT
-
google-site-verification=F6K27uCHt766bYaLFzIpxKVVvi8L6zNIRKtMXmsooM8zoho-verification=zb24601846.zmverify.zoho.com
Email authentication partial
- SPF
-
v=spf1 include:zohomail.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 37 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN, DENY- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self' https://coticsy.com https://*.coticsy.com;style-src 'self' 'unsafe-inline' https://coticsy.com https://*.coticsy.com https://fonts.googleapis.com https://cdnjs.cloudflare.com;font-src 'self' https://coticsy.com https://*.coticsy.com https://fonts.gstatic.com https://cdnjs.cloudflare.com;script-src 'self' 'unsafe-inline' https://coticsy.com https://*.coticsy.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://unpkg.com https://js.stripe.com https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com;img-src 'self' data: blob: https://coticsy.com https://*.coticsy.com https:;connect-src 'self' https://coticsy.com https://*.coticsy.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com;frame-src 'self' https://js.stripe.com https://hooks.stripe.com;base-uri 'self';form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none'- strict-transport-security
max-age=15552000; includeSubDomains, max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin