futurepost.app

.app crawl

First seen 2026-04-12 · Last seen 2026-04-12 · ok HTTP/1.1 200 3341 ms crawled 2026-05-20

US · 172.67.182.218 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
FuturePost - #1 Free FutureMe Alternative (2026)
Description
FuturePost is the best free FutureMe alternative. Write letters to your future self with no ads, no fees, and full privacy. Free iOS app included.
Language
en
Canonical
https://futurepost.app/

Open Graph

url
https://futurepost.app/
title
FuturePost – Write Letters to Your Future Self
locale
en_US
site name
FuturePost
description
FuturePost lets you write and schedule letters to your future self. Private, secure, distraction-free, and always free. Send digital time capsules with ease.

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • fonts.googleapis.com×2
  • embed.reddit.com×1
  • fonts.gstatic.com×1
  • www.googletagmanager.com×1

Social

DNS records live

NS
  • edward.ns.cloudflare.com
  • fatima.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
Verified for
  • Google

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:spf.mtasv.net ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:support@futurepost.app
policy: quarantine
DKIM
  • google: v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9HKVkL/uiHvjWup5qn+6xMDSSAmnF7ww937Gw2AYObfdwB8mOCOORstZufZjiSd6YLd+1s2jGJuwvy23…
selectors probed

Certificate (current)

E7
from 2026-05-18 to 2026-08-16
Expires in 87 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://futurepost.app/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https: data:; object-src 'none'; script-src 'self' https://challenges.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com 'nonce-MINw2q0FCMNS00auwVTA0w=='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; frame-src https://challenges.cloudflare.com; frame-ancestors 'none'; connect-src 'self' https://www.google-analytics.com https://challenges.cloudflare.com
strict-transport-security
max-age=63072000; includeSubDomains

Links to (4)

Linked from (1)