flowte.me
HTML metadata
Technology
- Server
- nginx
DNS records live
- NS
-
- ns-1334.awsdns-38.org
- ns-1891.awsdns-44.co.uk
- ns-532.awsdns-02.net
- ns-70.awsdns-08.com
- MX
-
- 10 30816303.in1.mandrillapp.com
- 20 30816303.in2.mandrillapp.com
- TXT
-
google-site-verification=IlqRvelmf32zlakeXAW5aFYSt81mebMcSAX5i_5u6MAgoogle-site-verification=YGo0aEhX4Spk2FxJHppa2A02gR9QufhkP145rf_2xiAv=spf1 include:spf.mandrillapp.com redirect=_spf.google.com ~all
Certificate (current)
Amazon RSA 2048 M01
Expires in 295 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- weak content type protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade, no-referrer-when-downgrade, no-referrer-when-downgrade, no-referrer-when-downgrade, no-referrer-when-downgrade, no-referrer-when-downgrade- x-content-type-options
nosniff, nosniff, nosniff, nosniff, nosniff, nosniff- content-security-policy
default-src * data: 'unsafe-eval' 'unsafe-inline', default-src * data: 'unsafe-eval' 'unsafe-inline', default-src * data: 'unsafe-eval' 'unsafe-inline', default-src * data: 'unsafe-eval' 'unsafe-inline', default-src * data: 'unsafe-eval' 'unsafe-inline', default-src * data: 'unsafe-eval' 'unsafe-inline'- strict-transport-security
max-age=3; includeSubDomains; preload, max-age=3; includeSubDomains; preload, max-age=3; includeSubDomains; preload, max-age=3; includeSubDomains; preload, max-age=3; includeSubDomains; preload, max-age=3; includeSubDomains; preload