deviceatlas.com
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Font Awesome
- Google Fonts
Third-party hosts loaded (10)
- fonts.googleapis.com×4
- cdn.devicevalidation.io×2
- js.hs-scripts.com×2
- use.fontawesome.com×2
- www.googletagmanager.com×2
- cdn.jsdelivr.net×1
- fonts.gstatic.com×1
- js.hsforms.net×1
- px.ads.linkedin.com×1
- script.crazyegg.com×1
Social
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 2007-11-29
- Expires
- 2026-11-29 192 days left
- Updated
- 2025-03-14
- Name servers
-
- colette.ns.cloudflare.com
- yew.ns.cloudflare.com
DNS records live
- NS
-
- colette.ns.cloudflare.com
- yew.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
bw=ONASFMgdqHAaOse3fVdmazEVolwkdImbrowSN1GeEwt2jamf-site-verification=PmNLA6grG05L-O61yf3GIg
- Verified for
-
- Apple
- Atlassian
- Microsoft 365
- OpenAI
Email authentication strong
- SPF
-
v=spf1 ip4:89.101.149.144/29 include:_spf.google.com include:_spf.da-tech.net include:_spf.psm.knowbe4.com include:20282853.spf07.hubspotemail.net -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; pct=100; fo=1; rua=mailto:dmarc@deviceatlas.com; ruf=mailto:dmarc@deviceatlas.compolicy: reject (enforced) · sp=reject - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC/w4rOO9R07zCy1E6Z5hgPiR3l4ctwIPdfoYbYYFFybXBdAs56BjZHxjvfhhWjfF3mm43eXMnmUa4VRAlh2H… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - mail:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqQFoKBfN/AGiiN557tOxX+8RQhb14SyvSu6hq8616bdeopJpd1GQwV3HPaLQHY2qvmQ88viQxg0ijLnZIFcnf4J9uc…
selectors probed - google:
Certificate (current)
Go Daddy Secure Certificate Authority - G2
Expires in 139 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' blob: https://*.hubspot.com https://*.hubspotfeedback.com https://*.hsforms.net https://*.hs-scripts.com https://*.hs-banner.com https://*.hs-analytics.net https://*.hsadspixel.net https://*.hsappstatic.net https://snap.licdn.com https://www.redditstatic.com https://*.crazyegg.com https://*.googletagmanager.com https://*.g2.com https://*.g2crowd.com https://*.factors.ai https://plugin.sopro.io https://*.devicevalidation.io https://*.deviceatlas.com https://cdn.jsdelivr.net https://*.dxpr.com https://grok.ie; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://cdn.jsdelivr.net https://*.dxpr.com; font-src 'self' data: https://fonts.gstatic.com https://use.fontawesome.com; img-src 'self' data: https:; connect-src 'self' https://*.google-analytics.com https://*.google.com https://*.hubspot.com https://*.hubapi.com https://*.hsforms.com https://*.hs-banner.com https://*.hsappstatic.net https- strict-transport-security
max-age=31536000; includeSubDomains