goodays.co
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
Third-party hosts loaded (1)
- res.cloudinary.com×45
Social
DNS records live
- NS
-
- ns1-37.azure-dns.com
- ns2-37.azure-dns.net
- ns3-37.azure-dns.org
- ns4-37.azure-dns.info
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 9 TXT records
google-site-verification=EN8zr5WcMen6KLehdTq3dPLyVdoJQYCQrC47aRQJbCwMS=ms80838568google-site-verification=ys0yWsg7LFh2Q1j0iQbHnwPEOr5q46_Qt7rA8nCvAZwZOOM_verify_nZkFUcP35LW6MI2BbqV1Hggoogle-site-verification=GEj3woT6kcFMNHzdmwVFUpTCUiFXROxYERfCv5ACLIUapple-domain-verification=6P9tTmJ1mbtkoWZOgoogle-site-verification=B9WxLN4txBQlugGjVAURWDurpp6Qcbdmz9-KJT5MB2Agoogle-site-verification=rFWtIZ5d2zeorNGreVVTb-K3PsbXoN7TmV2V_c87gRIgoogle-site-verification=M-H1MFvBtUK7nbcfXuWBAzEJvIY9XXn0vk_sO0I9Xt8
Email authentication strong
- SPF
-
v=spf1 include:sendgrid.net include:spf.mailjet.com include:_spf.google.com include:helpscoutemail.com include:1754530.spf02.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-reports@goodays.copolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkq1Rj6OYpIu8308dSLm7Opz0pm9quWecnsLgpxljVBfeja7R0JZYWSaY4b6KBaRcs2oXyH9YakGAWL… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4ralZvmVU+mzBczZP0PFq90NvEjcD6ZbWhESV/kNuNuWKoz4soBg6ndWUftsRONchJgsfphFnt7uQyxWLd… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIVyxEYl6PJMJiuZx4OxDtgp9/jsfDOXEZ9Y0P/guHDS2tgsxNarhsiUhsz62GbSz49Fs2/ZR2qB55C4yr5zUJBi…
selectors probed - google:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 49 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://www.youtube.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://js.hsforms.net https://player.vimeo.com https://static.hotjar.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hs-banner.com https://js.hubspot.com https://js.hs-analytics.net https://js.hscollectedforms.net https://js-na1.hs-scripts.com https://snap.licdn.com; connect-src 'self' 'unsafe-inline' https://vimeo.com https://region1.google-analytics.com https://pagead2.googlesyndication.com https://js.hs-banner.com https://api.hubapi.com https://cta-service-cms2.hubspot.com https://forms.hscollectedforms.net; img-src 'self' 'unsafe-inline' https://res.cloudinary.com https://teamtailor-production.s3.eu-west-1.amazonaws.com https://critizr-test.ams3.cdn.digitaloceanspaces.com https://assets.critizr.staging.verveagency.com https://assets.goodays.prod.verveagency.com https://images.team