getbantr.com
HTML metadata
Technology
- Server
- openresty
Third-party hosts loaded (4)
- assets.gumroad.com×9
- public-files.gumroad.com×3
- arjynae.gumroad.com×1
- static-2.gumroad.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2025-12-07
- Expires
- 2026-12-07 201 days left
- Updated
- 2025-12-07
- Name servers
-
- ns03.domaincontrol.com
- ns04.domaincontrol.com
DNS records live
- NS
-
- ns03.domaincontrol.com
- ns04.domaincontrol.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-gws-recovery-domain-verification=66363003google-site-verification=ia4bOJlkETkcRrULWnbse4wRBPr2suZHPvpO_LSVxMogoogle-site-verification=tRtMsAfTELLiqZhheB05qIJKRR1u89dYta7QcCPL9JA
Email authentication strong
- SPF
-
v=spf1 include:dc-aa8e722993._spfm.getbantr.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; sp=none; aspf=rpolicy: none (monitoring only) · sp=none - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 4 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src https 'self'; child-src * data: blob:; connect-src 'self' blob: www.dropbox.com api.dropboxapi.com s3.amazonaws.com/gumroad s3.amazonaws.com/gumroad/ s3.amazonaws.com/gumroad-public-storage s3.amazonaws.com/gumroad-public-storage/ gumroad-public-storage.s3.amazonaws.com gumroad-public-storage.s3.amazonaws.com/ www.google.com www.gstatic.com *.facebook.com *.facebook.net *.google-analytics.com *.g.doubleclick.net *.googletagmanager.com analytics.google.com *.analytics.google.com files.gumroad.com/ d1bdh6c3ceakz5.cloudfront.net/ *.braintreegateway.com www.paypalobjects.com *.paypal.com *.braintree-api.com iframe.ly help.gumroad.com unpkg.com/@lottiefiles/lottie-player@2.0.12/ gumroad.com wss://cable.gumroad.com assets.gumroad.com; font-src * data: blob:; frame-src * data: blob:; img-src * data: blob:; media-src * data: blob:; object-src * data: blob:; script-src 'self' 'unsafe-eval' ajax.cloudflare.com static.cloudflareinsights.com js.stripe.com api.stripe.com *.braintreegate