getgearnow.com
HTML metadata
Technology
- Server
- nginx
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×4
- fonts.gstatic.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2023-01-06
- Expires
- 2027-01-06 230 days left
- Updated
- 2026-01-26
- Name servers
-
- ns-1231.awsdns-25.org
- ns-14.awsdns-01.com
- ns-1771.awsdns-29.co.uk
- ns-573.awsdns-07.net
DNS records live
- NS
-
- ns-1231.awsdns-25.org
- ns-14.awsdns-01.com
- ns-1771.awsdns-29.co.uk
- ns-573.awsdns-07.net
Email authentication no MX
- SPF
- not published
- DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc@getgearnow.compolicy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 192 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer- permissions-policy
geolocation=(),microphone=(),midi=(),notifications=(),push=(),sync-xhr=(),camera=(),magnetometer=(),gyroscope=(),vibrate=(),fullscreen=(),payment=(self "https://js.stripe.com" "https://pay.google.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' https://www.google.com https://www.gstatic.com https://api.stripe.com https://maps.googleapis.com https://*.userpilot.io wss://*.userpilot.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google.com https://js.stripe.com https://maps.googleapis.com http://code.jquery.com https://*.gstatic.com https://ajax.googleapis.com https://malsup.github.io http://fast.fonts.net https://storage.googleapis.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' http://code.jquery.com https://fonts.googleapis.com http://cdn.jsdelivr.net http://fast.fonts.net; font-src 'self' https://fonts.gstatic.com; img-src * 'self' data: blob:; frame-src 'self' https://*.google.com https://js.stripe.com https://hooks.stripe.com youtube.com www.youtube.com www.youtube-nocookie.com blob: data:; frame-ancestors 'self' https://manage.chipplydev1.com https://manage.chipplydev2.com https://manage.chipplydev3.com https://manage.chipplydev4.com https://manage.chip- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin