gopass.org

.org crawl

First seen 2026-04-14 · Last seen 2026-05-08 · ok HTTP/1.1 200 716 ms crawled 2026-05-08

US · 104.18.15.38 · AS13335 Cloudflare, Inc.

Reputation 92/100 no dmarc policy

sector tech type homepage

HTML metadata

Title
GoPass
Language
en

Technology

CDN
Cloudflare
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.gstatic.com×1
  • script.crazyegg.com×1
  • translate.google.com×1

Registration

Registrar
Network Solutions, LLC
Created
2008-02-21
Expires
2031-02-21 1738 days left
Updated
2025-12-28
Name servers
  • guss.ns.cloudflare.com
  • rachel.ns.cloudflare.com

DNS records live

NS
  • guss.ns.cloudflare.com
  • rachel.ns.cloudflare.com
MX
  • 0 gopass-org.mail.protection.outlook.com
TXT
Show 4 TXT records
  • 4rbcbrzf2vgkv8k0fvgn50yndss2kgfp
  • MS=ms18494464
  • globalsign-domain-verification=ce91d8c16f170cc3cb9ec86897a04ca9
  • gopassorg.azurewebsites.net

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-05-04 to 2026-08-02
Expires in 74 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://gopass.org/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
script-src 'self' 'unsafe-inline' *.paymentwidget.com *.crazyegg.com *.jsdelivr.net *.cloudflare.com *.telerik.com *.msauth.net *.msftauth.net *.googletagmanager.com *.google.com *.jquery.com *.google-analytics.com *.aspnetcdn.com blob:; script-src-elem 'self' 'unsafe-inline' *.cybersource.com *.gstatic.com *.googleapis.com *.vixwhisper.com *.google.com *.googletagmanager.com *.crazyegg.com *.facebook.net; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.telerik.com *.aspnetcdn.com *.jsdelivr.net *.nativechat.com *.jquery.com *.typekit.net *.fontawesome.com; img-src 'self' data: *.google.com *.dart.org *.gstatic.com *.jsdelivr.net blob: *.windows.net *.googleapis.com w3.org/svg/2000 *.facebook.com ; font-src 'self' *.jsdelivr.net *.telerik.com *.gstatic.com *.googleapis.com *.fontawesome.com *.dart.org; frame-src 'self' *.vixwhisper.com *.cybersource.com *.google.com *.doubleclick.net *.googletagmanager.com;
strict-transport-security
max-age=31536000; includeSubDomains

Linked from (2)