firesphere.dev
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (2)
- cdn.jsdelivr.net×2
- bubbles.town×1
Social
Contact
- Phone
DNS records live
- NS
-
- coco.ns.cloudflare.com
- woz.ns.cloudflare.com
- MX
-
- 10 mail.protonmail.ch
- 20 mailsec.protonmail.ch
- TXT
-
protonmail-verification=826ef517808ecb6f81e5d8f761f62f4a2f4917fbgoogle-site-verification=41dIYxpU4IGOWaSfePMaLedZRzC2AGAEpdXij27HnuQ
Email authentication strong
- SPF
-
v=spf1 include:_spf.protonmail.ch include:spf.mailjet.com mx ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:42ec9c99b6d14366867bc1d765b1a3f1@dmarc-reports.cloudflare.netpolicy: quarantine - DKIM
-
- default:
v=DKIM1;t=s;p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAxflwWn0cqZXJPCnMMXiX5KWw1EEWfg6Dl9MKU0VnulgPm3vyqD/BKHgByUDdJEvwt4I66wbqyuE4EFxd/J… - dkim:
v=DKIM1;k=rsa;t=s;s=email;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsvtyAG2VltudgTCsX/EWdAWg/RchRDwo+SNOjL23cj+ufoEli4tuOGUWkP1jZeSJkKOK…
selectors probed - default:
Certificate (current)
R13
Expires in 88 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=('none'), ambient-light-sensor=('none'), autoplay=('self'), battery=('none'), camera=('none'), display-capture=('self' *), encrypted-media=('self'), fullscreen=('self'), geolocation=('none'), interest-cohort=('none')- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src 'self' https://piwik.firesphere.dev piwik.firesphere.dev; child-src https://staticcdn.co.nz; connect-src 'self' https://piwik.firesphere.dev piwik.firesphere.dev https://bubbles.town bubbles.town https://*.ingest.sentry.io *.ingest.sentry.io https://api.bloggify.net api.bloggify.net https://hcaptcha.com hcaptcha.com https://*.hcaptcha.com *.hcaptcha.com; font-src 'self' https://cdn.jsdelivr.net cdn.jsdelivr.net https://fonts.gstatic.com fonts.gstatic.com; form-action 'self'; frame-ancestors 'self'; frame-src https://hcaptcha.com hcaptcha.com https://*.hcaptcha.com *.hcaptcha.com https://www.youtube.com www.youtube.com https://staticcdn.co.nz staticcdn.co.nz https://staticcdn.co.nz; img-src 'self' https://piwik.firesphere.dev piwik.firesphere.dev https://avatars.githubusercontent.com avatars.githubusercontent.com https://bubbles.town bubbles.town blob: data:; media-src; object-src 'none'; script-src 'self' https://piwik.firesphere.dev piwik.firesphere.dev ht