generalmedicine.co
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- Vercel
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
- Ads
-
- Google Ads (DoubleClick)
Third-party hosts loaded (5)
- cdn.sanity.io×6
- googleads.g.doubleclick.net×1
- www.datadoghq-browser-agent.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns-1012.awsdns-62.net
- ns-1429.awsdns-50.org
- ns-1972.awsdns-54.co.uk
- ns-84.awsdns-10.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
- Apple
Email authentication strong
- SPF
-
v=spf1 include:dc-aa8e722993._spfm.generalmedicine.co include:mail.zendesk.com include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@generalmedicine.co;policy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtfX3ES4Ymxzkny6exQa71YCjxoMar7Jj/74AfJqHy0eAFW9MRRJ9CrtGvwyD9huTprBKckdekbmkU6E5QBQ…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 169 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self' https://generalmedicine.co https://*.generalmedicine.co https://api.generalmedicine.co https://assets.generalmedicine.co https://*.segment.generalmedicine.co; script-src 'self' https://generalmedicine.co https://*.generalmedicine.co https://api.generalmedicine.co https://assets.generalmedicine.co https://*.segment.generalmedicine.co https://googleads.g.doubleclick.net https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com https://cdn.segment.com https://www.datadoghq-browser-agent.com https://cdn.jsdelivr.net https://maps.googleapis.com https://*.stripe.com https://*.withpersona.com https://player.vimeo.com 'unsafe-eval' 'unsafe-inline' blob:; style-src 'self' https://generalmedicine.co https://*.generalmedicine.co https://api.generalmedicine.co https://assets.generalmedicine.co https://*.segment.generalmedicine.co https://*.googleapis.com https://*.gstatic.com data: blob: 'unsafe-inline'- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (5)
- facebook.com×1
- instagram.com×1
- legitscript.com×1
- tiktok.com×1
- x.com×1