dransay.com
HTML metadata
Technology
- CDN
- Cloudflare
Third-party hosts loaded (1)
- cdn.builder.io×162
Social
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 2021-05-27
- Expires
- 2032-11-11 2368 days left
- Updated
- 2022-11-11
- Name servers
-
- romina.ns.cloudflare.com
- yisroel.ns.cloudflare.com
DNS records live
- NS
-
- romina.ns.cloudflare.com
- yisroel.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 7 TXT records
google-site-verification=-hqx-kv74V21wo2o3rVSoK6aeutlRyS0_PGd9aLDprIgoogle-site-verification=CC9GC1HhJxxxTQ9MToQ7ozTY242Ux8u1dfqKg9DPzYYgoogle-site-verification=U094PNopkIVSAVa83cc8yr3rXzEaDcVxLtPZokB-7N4sendinblue-code:304882ea0efcf9f01771b8e6d9b58e03wiz-domain-verification=a112083cf60e535135d4ae921e2f35c7c5b718dece758569bf638cb789142abcatlassian-domain-verification=bvbZd4KENLpwcdFm/FhfxxR/P2BouTxGgD2qd8Et7FFrcXMcua/vN8GZqznLKSvCfacebook-domain-verification=j1g79l1guham8qpt4nnn5pdeux1ddw
Email authentication strong
- SPF
-
v=spf1 include:47999418.spf06.hubspotemail.net include:spf.sendinblue.com include:_spf.google.com mx ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:rua@dmarc.brevo.com; ruf=mailto:ruf@dmarc.brevo.compolicy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2N6aVGbl5reaBivCJL8HlFk1FbIStPoRpr3F1EGP7afXjXLy45nARXHvI5M+HeJOWO7Jbj3OSQinZS… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0aD2DZucJFfTXtyV2lmPHQa0ioEsXj/9J43LBraoAw7dkzH5HAWMdUL9tPATzMG/IXz+0wkzlYuLWwBPZm… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDtVFSmbuDKRb1tTSbUta3y3fS1UkxJTRC7I9JoZsLKE1Qcf2MZnPTybuTa+n+wjpLJOKo2jKCQRtDsJpcz5ElxtG…
selectors probed - google:
Certificate (current)
WE1
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
camera=(), microphone=(), geolocation=(self), payment=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://builder.io https://*.builder.io; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.api.here.com https://cdn.builder.io https://*.builder.io https://www.googletagmanager.com https://js.stripe.com https://*.crisp.chat https://sdk.frontnow.app https://*.frontnow.app https://sg.dransay.com https://analytics.ahrefs.com https://*.usercentrics.eu https://*.posthog.com https://*.i.posthog.com https://analytics.cnd-motionmedia.de https://cdn.rudderlabs.com https://www.youtube.com https://*.hotjar.com https://t.adcell.com https://p.gsitrix.com https://o.gsitrix.com https://s.adroll.com https://d.adroll.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.redditstatic.com https://*.optimeleon.com; style-src 'self' 'unsafe-inline' https://js.api.here.com https://cdn.builder.io https://fonts.googleapis.com https://*.crisp.chat https://*.frontnow.app https://*.posthog.com https://*.usercentrics.eu https://*.h- strict-transport-security
max-age=15552000