dnapayments.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- widget.trustpilot.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- 101domain GRS Limited
- Created
- 2018-03-22
- Expires
- 2027-03-22 307 days left
- Updated
- 2022-02-21
- Name servers
-
- ns1.p68.dns.oraclecloud.net
- ns2.p68.dns.oraclecloud.net
- ns3.p68.dns.oraclecloud.net
- ns4.p68.dns.oraclecloud.net
DNS records live
- NS
-
- ns1.p68.dns.oraclecloud.net
- ns2.p68.dns.oraclecloud.net
- ns3.p68.dns.oraclecloud.net
- ns4.p68.dns.oraclecloud.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 5 TXT records
google-site-verification=gE4ZSFnoWEppY7W5c12eXJdpRecSX9wzTBXX1WrJYlkgoogle-site-verification=KGiTsWnxAQJ0EDAjnMJXG7s5fodFcTjwEY5-niND1Boatlassian-domain-verification=Y4VYH2gCqSg4vznG8ka2vTlvoO13YP5AzGTtNG9rQAqy/SGSNYMQFpTbCbjthu9F23j3039xkb6fpljrgxd1gqwbfqpbrtfbapple-domain-verification=FGO2jtjwfgepCamV
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@dnapayments.com; ruf=mailto:dmarc@dnapayments.compolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIPvz5prc+wN2nxLKpSZ8g6gkQrfW5jCUuX7OQCRPeJWUjiJgwTl+MXtKrXZI3lL5uqWSKdZQrRha+lbtSHF… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqJ9HiRsQKUcw0mm/6nP2EZRrv5HLtXNT28JF2hx33eyQ/tKPeCGrO/gpbZ/dfF9TXCM3ZIEhBDiVBg5OmL… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmgCnHK9SU8sNx3neaEVpoSod0qNj+H7G98zru0XZt3VI3NhyLxQ1SwV3rUOFCikj5nGGIE00wwJrJWtK4a…
selectors probed - google:
Certificate (current)
E8
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
deny- permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://aichatbot.sendbird.com https://aiagent.delight.ai https://*.trustpilot.com https://*.survicate-cdn.com https://*.lfeeder.com https://*.survicate.com https://*.kodif.io https://*.gstatic.com https://*.google.com https://*.zdassets.com https://www.youtube.com https://*.googleapis.com https://*.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.survicate-cdn.com https://*.googleapis.com data:; img-src 'self' data: https://*.sendbird.com https://s3.eu-central-1.amazonaws.com/sendbird-eu-1 https://*.lfeeder.com https://*.youtube.com https://*.ytimg.com https://*.gstatic.com https://*.googleapis.com; connect-src 'self' https://*.sendbird.com wss://*.sendbird.com https://*.survicate.com wss://*.zopim.com https://*.zendesk.com https://*.zdassets.com https://*.google-analytics.com https://*.googleapis.com; font-src 'self' https://*.survicate-cdn.com https://*.gstatic.com data: ; object-src 'none'; child-s- strict-transport-security
max-age=31536000; includeSubDomains