designcode.io
HTML metadata
Technology
- CDN
- Netlify
- CMS
- Gatsby
Third-party hosts loaded (4)
- js.stripe.com×1
- m.stripe.com×1
- q.stripe.com×1
- stripe.com×1
Contact
DNS records live
- NS
-
- dns1.p03.nsone.net
- dns2.p03.nsone.net
- dns3.p03.nsone.net
- dns4.p03.nsone.net
- MX
-
- 10 mx.designcode.io.cust.b.hostedemail.com
- 10 mx1.mail.name.com
- 10 mx2.mail.name.com
- 10 mx3.mail.name.com
- TXT
-
Show 9 TXT records
google-site-verification=9_rHRgSsiOvHauN_t4SR9thBWHvUqHfpJ-vKbnYkcZsgoogle-site-verification=eVsLSljl5ZLeIaevRj122-IxVj_pAmImasAkGzwU_gsv=spf1 include:servers.mcsv.net ?allv=spf1 include:_spf.hostedemail.com ~allv=spf1 include:_spf.firebasemail.com ~allv=spf1 include:mailgun.org ~allv=spf1 a mx ~allfirebase=designcodeiosendinblue-code:19ab15ca7fda49610f372881ebc71241
Certificate (current)
E8
Expires in 69 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
ALLOWALL- permissions-policy
geolocation=("https://www.google-analytics.com/"), payment=("https://js.stripe.com" "https://www.paypal.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self' www.googletagmanager.com https://www.google-analytics.com/analytics.js https://js.stripe.com/v3; base-uri 'self'; frame-src https://js.stripe.com https://www.paypal.com/ https://www.paypalobjects.com https://player.vimeo.com/ https://app.netlify.com/; img-src 'self' data: blob: https://www.googletagmanager.com https://t.paypal.com https://www.paypalobjects.com https://images.ctfassets.net/ https://d33wubrfki0l68.cloudfront.net https://firebasestorage.googleapis.com/ https://www.google-analytics.com; connect-src 'self' https://api-js.mixpanel.com https://images.ctfassets.net/ https://*.cloudfront.net https://js.stripe.com/v3/ https://www.paypal.com/ https://www.paypalobjects.com https://netlify-cdp-loader.netlify.app/netlify.js www.googleapis.com https://firebasestorage.googleapis.com https://api.dropboxapi.com/ www.figma.com https://cdn.contentful.com/ https://vimeo.com/ https://firestore.googleapis.com/ https://us-central1-designcodeio.cloudfunctions.net/ https://ww- strict-transport-security
max-age=31536000