ekspeer.com

.com crawl

First seen 2026-04-29 · Last seen 2026-04-29 · ok HTTP/1.1 200 2105 ms crawled 2026-05-07

US · 104.198.14.52 · AS396982 Google LLC

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Expense Tracker & Budget App - Track Subscriptions & Expenses | ekspeer
Description
Track expenses, subscriptions, budgets, and multi-currency spending in one place with ekspeer. Free expense tracker app with automatic currency conversion and budget management. Free plan available.
Language
en
Canonical
https://ekspeer.com/

Open Graph

url
https://ekspeer.com/
title
Expense Tracker & Budget App - Track Subscriptions & Expenses | ekspeer
site name
ekspeer
description
Track expenses, subscriptions, budgets, and multi-currency spending in one place with ekspeer. Free expense tracker app with automatic currency conversion and budget management. Free plan available.

Technology

CDN
Netlify
Analytics
  • Google Tag Manager
Cookie consent
  • Cookiebot

Third-party hosts loaded (2)

  • www.googletagmanager.com×3
  • consent.cookiebot.com×2

Social

Contact

Email

Registration

Registrar
Name SRS AB
Created
2025-03-12
Expires
2027-03-12 297 days left
Updated
2026-01-29
Name servers
  • algin.ns.cloudflare.com
  • athena.ns.cloudflare.com

DNS records live

NS
  • algin.ns.cloudflare.com
  • athena.ns.cloudflare.com
MX
  • 10 in1-smtp.messagingengine.com
  • 19 in2-smtp.messagingengine.com
TXT
  • brevo-code:b2f86fe4e7af07782d0477fa4ebdb37d
  • google-site-verification=a6gR0IHSzhJ9pDDOGd-VutEdrdcbERyh19winIp3WA4
  • google-site-verification=pYSSl4imroaE8lby-qvDDlGp47E3Dlp2h1JyxfvGYP0

Email authentication partial

SPF
not published
DMARC
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com
policy: none (monitoring only)
DKIM
  • default: v=DKIM1; p=
  • google: v=DKIM1; p=
  • selector1: v=DKIM1; p=
  • selector2: v=DKIM1; p=
  • k1: v=DKIM1; p=
  • k2: v=DKIM1; p=
  • mail: v=DKIM1; p=
  • dkim: v=DKIM1; p=
  • s1: v=DKIM1; p=
  • s2: v=DKIM1; p=
  • mxvault: v=DKIM1; p=
  • smtpapi: v=DKIM1; p=
selectors probed

Certificate (current)

E8
from 2026-03-31 to 2026-06-29
Expires in 42 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://ekspeer.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
camera=(), microphone=(), geolocation=(self), payment=(), usb=(), serial=(), midi=(), magnetometer=(), gyroscope=(), accelerometer=(), ambient-light-sensor=(), autoplay=(self), encrypted-media=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), fullscreen=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), picture-in-picture=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), display-capture=(), web-share=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://consent.cookiebot.com https://t.contentsquare.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' data: https: blob: https://startupfa.me https://indiehunt.io; media-src 'self' https:; object-src 'none'; base-uri 'self'; frame-src https://www.googletagmanager.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.youtube.com https://www.youtube-nocookie.com; frame-ancestors 'self'; form-action 'self' https://nfknzkquayqaecbcwzkd.supabase.co; connect-src 'self' https://nfknzkquayqaecbcwzkd.supabase.co https://*.supabase.co wss://nfknzkquayqaecbcwzkd.supabase.co wss://*.supabase.co https://www.google-analytics.com https://region1.google-analytics.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://api-inference.huggingface.co https://api
strict-transport-security
max-age=31536000; includeSubDomains; preload
cross-origin-opener-policy
same-origin-allow-popups
cross-origin-embedder-policy
unsafe-none
cross-origin-resource-policy
cross-origin

Links to (8)

Linked from (1)