figlab.com

.com crawl

First seen 2026-05-04 · Last seen 2026-05-11 · ok HTTP/1.1 200 5668 ms crawled 2026-05-11

US · 15.197.225.128 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

sector other type landing page

HTML metadata

Title
About
Language
en-US

Open Graph

url
https://www.figlab.com/
title
About
description
FACILITIES The FIGLAB is located at 407 South Craig Street at the western edge of Carnegie Mellon’s campus. Our century-old, LEED-certified building contains three studios for rapid ideation and prototyping, encompassing more than 1500 square feet of shop space. One lab is dedicated to electronics

Technology

Server
ESF
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (5)

  • fonts.googleapis.com×2
  • lh3.googleusercontent.com×2
  • www.gstatic.com×2
  • apis.google.com×1
  • www.googletagmanager.com×1

Registration

Registrar
GoDaddy.com, LLC
Created
2010-01-25
Expires
2028-01-25 615 days left
Updated
2026-01-26
Name servers
  • ns09.domaincontrol.com
  • ns10.domaincontrol.com

DNS records live

NS
  • ns09.domaincontrol.com
  • ns10.domaincontrol.com
MX
  • 0 smtp.secureserver.net
  • 10 mailstore1.secureserver.net
TXT
  • D3802436
  • google-site-verification=rrE0RYV5LHhMqR3j1p6ko12Jtf8I7xEj9P9Tcy_7yyI

Email authentication weak

SPF
not published
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

GoDaddy TLS Intermediate CA DV - R1v1
from 2026-03-15 to 2026-09-30
Expires in 133 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.figlab.com

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-lik0pOoSBmwgP0yrEQu8uA' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/
cross-origin-opener-policy
unsafe-none
cross-origin-resource-policy
same-site

Links to (1)

Linked from (1)