gearset.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Osano
Third-party hosts loaded (5)
- assets.calendly.com×1
- cmp.osano.com×1
- www.g2.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2003-05-03
- Expires
- 2030-05-03 1443 days left
- Updated
- 2021-03-30
- Name servers
-
- ali.ns.cloudflare.com
- yichun.ns.cloudflare.com
DNS records live
- NS
-
- ali.ns.cloudflare.com
- yichun.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 5 TXT records
IDznKfdoGekcCdGOu9gklWdEZgAb58pGOFt++YOBI/DzzhyVMqrdK92oWzLIu1W0Wt+8zigZO2u0EI2HgVo40Q==jamf-site-verification=ylBoJjMWgBRYXGgulINEFAuber-domain-verification=5de4459d-0ad1-4d76-bda4-a0cf06f0af43MS=E2E516CDF2549C184149028D9845BFC2E384308DTn7MtrwTX8oaVUjLzS_wTX1otZZZ
- Verified for
-
- Ahrefs
- Anthropic
- Apple
- DocuSign
- Microsoft 365
- Notion
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:145855607.spf03.hubspotemail.net include:spf.mandrillapp.com include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:emsd1.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:email-status-notifications@gearset.com,mailto:0f31b73ed7@rua.easydmarc.eu; ruf=mailto:0f31b73ed7@ruf.easydmarc.eu; fo=1policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAiSGBOcrITxGeinfzYXu3TjLBcVBfLl+f2m94+XzDHG/Si/WeAO+RWsyNRdrNept9VX70OxGfADZcqN… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - google:
Certificate (current)
WE1
Expires in 60 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'unsafe-inline' 'unsafe-eval' https: http: 'strict-dynamic' 'nonce-PleIuk8J1TMZbnbMmMgFtQ==' 'wasm-unsafe-eval'; default-src 'self' gearset.com *.gearset.com *.google.com *.wistia.com *.wistia.net; media-src 'self' *.wistia.com *.wistia.net *.intercomcdn.com *.intercomcdn.eu blob: data:; font-src 'self' data: *.gearset.com gearset.com *.wistia.com *.wistia.net *.gartner.com *.intercomcdn.com *.mouseflow.com; connect-src 'self' gearset.com *.gearset.com wss://trust.gearset.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.google.com *.linkedin.com px.ads.linkedin.com *.reddit.com *.redditstatic.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.- strict-transport-security
max-age=15552000; includeSubDomains; preload