gopass.org
HTML metadata
Technology
- CDN
- Cloudflare
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.gstatic.com×1
- script.crazyegg.com×1
- translate.google.com×1
Registration
- Registrar
- Network Solutions, LLC
- Created
- 2008-02-21
- Expires
- 2031-02-21 1738 days left
- Updated
- 2025-12-28
- Name servers
-
- guss.ns.cloudflare.com
- rachel.ns.cloudflare.com
DNS records live
- NS
-
- guss.ns.cloudflare.com
- rachel.ns.cloudflare.com
- MX
-
- 0 gopass-org.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
4rbcbrzf2vgkv8k0fvgn50yndss2kgfpMS=ms18494464globalsign-domain-verification=ce91d8c16f170cc3cb9ec86897a04ca9gopassorg.azurewebsites.net
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 74 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' *.paymentwidget.com *.crazyegg.com *.jsdelivr.net *.cloudflare.com *.telerik.com *.msauth.net *.msftauth.net *.googletagmanager.com *.google.com *.jquery.com *.google-analytics.com *.aspnetcdn.com blob:; script-src-elem 'self' 'unsafe-inline' *.cybersource.com *.gstatic.com *.googleapis.com *.vixwhisper.com *.google.com *.googletagmanager.com *.crazyegg.com *.facebook.net; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.telerik.com *.aspnetcdn.com *.jsdelivr.net *.nativechat.com *.jquery.com *.typekit.net *.fontawesome.com; img-src 'self' data: *.google.com *.dart.org *.gstatic.com *.jsdelivr.net blob: *.windows.net *.googleapis.com w3.org/svg/2000 *.facebook.com ; font-src 'self' *.jsdelivr.net *.telerik.com *.gstatic.com *.googleapis.com *.fontawesome.com *.dart.org; frame-src 'self' *.vixwhisper.com *.cybersource.com *.google.com *.doubleclick.net *.googletagmanager.com;- strict-transport-security
max-age=31536000; includeSubDomains