fortifi.io
HTML metadata
Technology
- Server
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns-cloud-b1.googledomains.com
- ns-cloud-b2.googledomains.com
- ns-cloud-b3.googledomains.com
- ns-cloud-b4.googledomains.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 10 TXT records
fortifi-domain-verification=iRrFjPG8UJbvMkP32sgzIeFCxhEszZHd38PyyYdYYe0hl97ctG8jEIe6JVAfbxCugoogle-site-verification=hQWX5tmSGkK8cmzs3xhwsuNQ-CVfogHaehxU08z82YAgoogle-site-verification=tPKu8OulerB8bXT8WVE1uu2czm_tQawvibf1klnGf5Egoogle-site-verification=NxiCWeJipF13jT1LA2RhlEzVpa9AMjK1aWA1RiGSj_Ygoogle-site-verification=C8N8goG8mw-sCsw_rb_M97YgksDcX7I1VHrm2BjLvS4access-domain-verification=4f11e707da2e277861cd4c4c2af905789d6254dc448076c2a8a9175c07d8926cgoogle-site-verification=1DYjWSGwLWtqb3QEw_yYBTTRbheaKDEw5VTfkYg_XFQworkplace-domain-verification=8jm9iRvDKvr4LM5kSjngsMFOWasZCDgoogle-site-verification=wK_0qaYOcCyPELeSAJLjwvpa6HLvxOZQJ0ohue5DIWogoogle-site-verification=Xl0Taxtc3uBpdVQ_VhvJLyVwhHG_-avV2nYa4VWvZbA
Email authentication weak
- SPF
-
v=spf1 include:_spf.google.com include:u123456.wl.sendgrid.net include:em6838.fortifi.io ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1dTI2Av5QM9geLyR80O2flDMA992ca9oYQ45yv66HI5D2r35/ddcfhrtRTZDL++R+a0CHrg7vaZZGzShCB… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCcvRTKole+UlE9D2EaQ5+9SNca2ZTdiRh+kUq+ozSLZ6C4wQPcm0ekKrR4gtltEVKmbGI4JElH2fLjQ/LGZKRK42…
selectors probed - s1:
Certificate (current)
WR3
Expires in 48 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://cdn.fortifi.io https://url.fortifi.io https://chat.fortifi.io https://cfgchat.fortifi.io https://www.google-analytics.com https://www.google.com https://www.facebook.com https://*.hotjar.com https://*.hotjar.io https://fortifi.io; connect-src wss://chat.fortifi.io https://*.hotjar.com wss://*.hotjar.com wss://*.hotjar.io https://fortifi.io; style-src 'unsafe-inline' https://chat.fortifi.io https://fonts.googleapis.com https://fortifi.io; font-src https://chat.fortifi.io https://fonts.gstatic.com https://fortifi.io; script-src 'unsafe-inline' https://url.fortifi.io https://chat.fortifi.io https://cfgchat.fortifi.io https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://connect.facebook.net https://www.facebook.com https://*.hotjar.com https://*.hotjar.io https://secure.hiss3lark.com https://fortifi.io- strict-transport-security
max-age=31536000; includeSubDomains; preload