dwellapp.io

.io crawl

First seen 2026-04-21 · Last seen 2026-05-18 · ok HTTP/1.1 200 878 ms crawled 2026-05-15

US · 172.66.40.215 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

sector religion type app saas

HTML metadata

Title
Dwell — Audio Bible App
Description
Discover the Power of Listening to the Bible. Bring the teachings and stories of Scripture to life, not just reading the words, but hearing them read over you
Language
en

Open Graph

title
Audio Bible App
site name
Dwell Bible
description
Discover the Power of Listening to the Bible

Technology

CDN
Cloudflare
Analytics
  • Fathom

Third-party hosts loaded (5)

  • cdn.usefathom.com×1
  • js.sentry-cdn.com×1
  • kit.fontawesome.com×1
  • script.tapfiliate.com×1
  • www.facebook.com×1

Social

DNS records live

NS
  • dayana.ns.cloudflare.com
  • terin.ns.cloudflare.com
MX
  • 10 work-mx.app.hey.com
TXT
Show 6 TXT records
  • google-site-verification=5JTAKg46ayezqJeSa5ksO3jHM1QKgt95NTaRfAv-AH0
  • google-site-verification=uAq4HF6qJxOBPLR-S-y86RIUL3oFEw2r41HR-f_64Ro
  • google-site-verification=x5hK1YYwbGXVfr3BINLxzZf0orKhLv7k3NIRZCwUNug
  • hey-verification:RNKLRqRY461uvEgjNQeh9TFB
  • stripe-verification=7391bbec1c8ff25282251a86bab0777d98638a96510b2821a2075d4252ec4ad3
  • ahrefs-site-verification_c48e620b23402687a319b1ec919dc1d74401f49b5e03ecd194e1d9582aa3a3fd

Email authentication partial

SPF
v=spf1 include:_spf.hey.com include:spf.mandrillapp.com include:servers.mcsv.net include:spf.tapfiliate.com include:helpscoutemail.com include:shops.shopify.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none
policy: none (monitoring only)
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

WE1
from 2026-04-04 to 2026-07-03
Expires in 45 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://dwellapp.io/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'none'; font-src 'self' https: data:; img-src 'self' https: data: blob:; object-src 'none'; worker-src 'self' https: blob:; connect-src 'self' https: itms-appss://apps.apple.com; child-src 'self' blob:; media-src 'self' https: blob:; frame-src 'self' https:; script-src 'self' https: 'unsafe-inline'; style-src 'self' https: 'unsafe-inline'
strict-transport-security
max-age=63072000; includeSubDomains

Links to (6)

Linked from (2)