dgrammatiko.dev
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
Third-party hosts loaded (3)
- webmention.io×2
- bsky.app×1
- github.com×1
Social
DNS records live
- NS
-
- sara.ns.cloudflare.com
- tom.ns.cloudflare.com
- MX
-
- 10 mail.protonmail.ch
- 20 mailsec.protonmail.ch
- TXT
-
google-site-verification=gazqVbs-ndNbOzH-R4aGlspoAZaCQY6xaI9roOLD_rQprotonmail-verification=7f68411437eda7967b5f319d82241d9c7977310fgoogle-site-verification=bC3WvVb4jdkwggLtx9L_IKt5Xje-5EswGJ3Z9sygo8g
Email authentication strong
- SPF
-
v=spf1 include:_spf.protonmail.ch mx ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:d239b68bd3314fe3ae863875184ae68a@dmarc-reports.cloudflare.net;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 56 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; default-src 'none'; style-src 'self'; script-src 'self' 'inline-speculation-rules' https://www.youtube.com https://static.cloudflareinsights.com; img-src 'self' https://webmention.io https://avatars.webmention.io *.amazonaws.com data: https://i.ytimg.com; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com; connect-src 'self' https://cloudflareinsights.com/cdn-cgi/rum; object-src 'none'; font-src 'self'; frame-ancestors 'self'; form-action 'self'; base-uri 'none'; manifest-src 'self';- strict-transport-security
max-age=63072000; includeSubDomains; preload