dorahacks.io
HTML metadata
Technology
- CMS
- Nuxt
- Analytics
-
- Google Tag Manager
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (4)
- cdn.jsdelivr.net×2
- www.youtube.com×2
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns-1086.awsdns-07.org
- ns-1729.awsdns-24.co.uk
- ns-37.awsdns-04.com
- ns-653.awsdns-17.net
- MX
-
- 10 mxa.mailgun.org
- 10 mxb.mailgun.org
- TXT
-
google-site-verification=RSCn-oXMFR07rzr02-uKr7CG9jLQJ1mb_TkyUdjxV9Igoogle-site-verification=Fmqy1l7H6XKrHDPasQAVw7-FOgHFQMrG02gdD5V4r_M
Email authentication strong
- SPF
-
v=spf1 include:mailgun.org -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:admin@dorafactory.orgpolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCYUUGVSmgxeQO6O6X4jI3faoMMp42nX8rxMHfLN9PxUZpmr0fNeJJeiXcmJ2skIAj8m/P480F3af21JEyNKz…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 213 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
Header values
- referrer-policy
origin-when-cross-origin- permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; font-src 'self' https: data:; form-action 'self'; frame-ancestors 'self' https://responsiveviewer.org https://dev.events; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline';- strict-transport-security
max-age=15552000; includeSubDomains;
Links to (8)
- binance.com×3
- dorafactory.org×3
- facebook.com×3
- instagram.com×3
- linkedin.com×3
- t.me×3
- twitter.com×3
- youtube.com×3