floqast.app
HTML metadata
Technology
Third-party hosts loaded (1)
- static.floqast.com×3
DNS records live
- NS
-
- ns-1156.awsdns-16.org
- ns-1589.awsdns-06.co.uk
- ns-229.awsdns-28.com
- ns-759.awsdns-30.net
- MX
-
- 10 mxa.mailgun.org
- 10 mxb.mailgun.org
- TXT
-
Show 5 TXT records
_tv3inh26hy22w1r61l1z1cv6s5thwthgoogle-site-verification=aNnWB94ziuRqD2St1siuODGX-615F8iKobIQO_-Dm7Ygoogle-site-verification=dV6z_htzlwx9llhpRDvtrMVaETn0X5IFQzTeTvmlPyQprojectdiscovery-verification=a1c80e30dd_fvbatbaoh96wtxwqgthgkabroowadyq
Email authentication partial
- SPF
-
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:mailgun.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.emailpolicy: none (monitoring only) - DKIM
-
- k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDONsC7TwszOVKO702nbqeIoBv/9jjqx0lEjPdL0+9r+dUptQBZcTqceCaBdJmrGkLNUzDWJ/lNABGbnj51TS+2VVrV3tX…
selectors probed - k1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 151 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
script-src 'self' blob: https://js.pusher.com https://sockjs-mt1.pusher.com https://stats.pusher.com https://static.floqast.app https://static.floqast.com https://services.floqast.app https://resource-maps.floqast.app https://fq-production-internal-ip-restricted.s3-us-west-2.amazonaws.com https://super-assets.floqast.app *.aptrinsic.com https://cdnjs.cloudflare.com 'wasm-unsafe-eval' *.split.io 'sha256-C7d5o70ttR1JoqTWMb2B136SH86g8sTU6bx8hhug0i4=';style-src 'self' 'unsafe-inline' https://fonts.googleapis.com http://static.floqast.app https://static.floqast.com https://services.floqast.app https://fq-production-internal-ip-restricted.s3-us-west-2.amazonaws.com https://super-assets.floqast.app https://fonts.gstatic.com *.aptrinsic.com;img-src 'self' blob: data: https://s3.amazonaws.com https://s3-us-west-2.amazonaws.com https://static.floqast.app https://services.floqast.app https://static.floqast.com https://fq-production-internal-ip-restricted.s3-us-west-2.amazonaws.com https://super-a- strict-transport-security
max-age=31536000; includeSubDomains