dreamz.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
Third-party hosts loaded (2)
- imagedelivery.net×19
- images.ctfassets.net×1
Social
Registration
- Registrar
- NameCheap, Inc.
- Created
- 1997-09-28
- Expires
- 2027-09-27 495 days left
- Updated
- 2024-08-28
- Name servers
-
- jessica.ns.cloudflare.com
- mario.ns.cloudflare.com
DNS records live
- NS
-
- jessica.ns.cloudflare.com
- mario.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 4 TXT records
google-site-verification=-v1OCb2v3RAICEqlq7eEsqgk1Pb52WeS_IzfCKX5Uq0google-site-verification=Nl_KKa_f48P2jJJMKr0jiFy6kY1vOtaP8DdTmcCcdG8google-site-verification=p_ZiBccMggJGbLL6ZUvtII24Vi93ZxWJXjdGPL2AIssv=spf1 include:spf.zoho.eu include:eu.transmail.net include:mail.zendesk.com ~all
Certificate (current)
WE1
Expires in 27 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' *; base-uri 'self' optimize.google.com; frame-src data: *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' *; font-src 'self' data: * *.googleapis.com *.gstatic.com *.zohocdn.com; img-src 'self' data: * imagedelivery.net *.videodelivery.net *.cloudflarestream.com *.mw.zone; media-src 'self' *.olark.com *.zohocdn.com *.ctfassets.net imagedelivery.net videodelivery.net *.cloudflarestream.com *.mw.zone;- strict-transport-security
max-age=15552000; includeSubDomains; preload