dropsecure.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Termly
- Fonts
-
- Google Fonts
- Social widgets
-
- LinkedIn Widget
Third-party hosts loaded (10)
- d2aflwvi9j2hxt.cloudfront.net×75
- capterra.s3.amazonaws.com×4
- fonts.googleapis.com×2
- www.googletagmanager.com×2
- app.termly.io×1
- assets.capterra.com×1
- fonts.gstatic.com×1
- js-na1.hs-scripts.com×1
- platform.linkedin.com×1
- www.facebook.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2013-07-09
- Expires
- 2026-07-09 50 days left
- Updated
- 2025-07-10
- Name servers
-
- ns29.domaincontrol.com
- ns30.domaincontrol.com
DNS records live
- NS
-
- ns29.domaincontrol.com
- ns30.domaincontrol.com
- MX
-
- 10 mx.zoho.com
- 20 mx2.zoho.com
- TXT
-
google-site-verification=qfsJPqXQryinv9t5i8SQT32hXJGlSI2-DcmrYfhwi3Ygoogle-site-verification=MVNJdbVwGHGbiXht69li7z0HWIUQRMHc53MUVNjtpEYgoogle-site-verification=HRbStx6-7cCXlwziqaIjqowQUOnBUw7Q6QGNjrRje-E
Email authentication strong
- SPF
-
v=spf1 a mx ip4:54.70.89.105 include:spf.braintreegateway.com include:zoho.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:postmaster@dropsecure.compolicy: reject (enforced) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5sUxC5wZdL/lOt/AW1z43Yw0y0BSyqb70fMus9ndA92csIseHvC2n+gKXLQ1cpD9+uKk43ieABknjQxByv… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt6I0rsQ6oAjyz/pfCABAE153veZSCVXDg9ULSLwmR0owY540NfdrNUSG8sje8CpI5eSkZQ1RmH9M+4xqgM…
selectors probed - k2:
Certificate (current)
R12
Expires in 46 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()- x-content-type-options
nosniff- content-security-policy
script-src 'unsafe-inline' 'unsafe-eval' dropsecure.com *.dropsecure.com api.hubspot.com *.hubspot.com www.googletagmanager.com *.googletagmanager.com gs-cdn.optimonk.com googleads.g.doubleclick.net snap.licdn.com js.hs-scripts.com front.optimonk.com js.hs-analytics.net js.usemessages.com js.hs-banner.com js.hsadspixel.net www.linkedin.com www.google-analytics.com platform.linkedin.com js-na1.hs-scripts.com app.termly.io www.linkedin.com js.hsforms.net www.google.com www.gstatic.com- strict-transport-security
max-age=31536000; includeSubDomains