greatexpectations.io
HTML metadata
Technology
- CDN
- Netlify
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- images.ctfassets.net×5
- www.googletagmanager.com×4
- cookiehub.net×1
- dev.visualwebsiteoptimizer.com×1
- fast.wistia.com×1
- js.hs-scripts.com×1
Social
DNS records live
- NS
-
- ns-1240.awsdns-27.org
- ns-1738.awsdns-25.co.uk
- ns-404.awsdns-50.com
- ns-649.awsdns-17.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 15 TXT records
ZOOM_verify_Jz9YlLEzsgFueSuU3Ovch5bw=WIAXzdw1jdi+BWalhTygjD+BCbzjL0vnES3kuhg2wRSkcursor-domain-verification-dk57tf=sDJuyY3BtdlyVefQa1Lg1tETkMS=ms17709518miro-verification=ea1ff03827337830df8b0e3d34d2b55e6f6ffbe3google-site-verification=uHbbSBzXW-VouK3ifzv9l60CgeB3MZ54oeCx8mjuDwUgoogle-site-verification=OnJTZWx8hfLLIixI1oIu7nhOG2RSfeUjFzYxvUaYubMamazon-business-verification=250ae18445e23fced0a0e6c483134cfbe862f4020a03c9470405fd4fa2955ae324D6CA7892lucid-verification=hy5j4m9oa9a2mv8l0msxatlassian-domain-verification=lJyKS3xDXIl1C6a/9aeVtxzvUI1WiLUaJiELbPDdqktfV32g31F6j2lBS1XodVwJhubspot-domain-verification=MDY2ZDRlMWUtODM5NS00MjQwLTk4NDAtOTY1YTAyZjRjMmEwapple-domain-verification=ypZyrYFh3wZVGxqdhcp-domain-verification=8ca5ee6f3ac8f40c884b39c4c8c24f06d6ac9329e92a0ba04137cfdc6926a36cslack-domain-verification=pa7rjkm68giheBILf9vmRNk7E14ebCRBqvzchBG7
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:sendgrid.net include:calendar-server.bounces.google.com include:39553814.spf10.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.emailpolicy: quarantine - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCDXZ4zy1A53W89f1GFm3ohu22h/g779ou8KwiWaD1Uoqmx//GJwlgO6sRoOti5k2+EB+t68go4rqQ6K6jgQ3… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsbl699gKTUH8pH9Q5ZZtkhF52deiY66sLa/Oie6NDprI307cu7oD4fNF/q0kUdKKU5EG/0mGSNY5cs8jtW… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxKFfXkMtpScGjKqWlAGR3x2Ndk4m+kL271oMBIgxsnvsRaZHmfSvB07NVrcPtvHHxxtsIdVedAPc2PawVa…
selectors probed - google:
Certificate (current)
E7
Expires in 51 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' dev.visualwebsiteoptimizer.com www.google.de www.google.ca www.google.com www.google-analytics.com; worker-src 'self' blob: 'unsafe-eval'; font-src 'self' data: fonts.gstatic.com fast.wistia.com; style-src 'self' 'unsafe-inline' cookiehub.net forms.hsforms.com fonts.googleapis.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' ajax.googleapis.com js.hubspot.com js.hsforms.com js.hsforms.net www.googletagmanager.com app.posthog.com cdn.cr-relay.com fast.wistia.com dev.visualwebsiteoptimizer.com cookiehub.net us-assets.i.posthog.com static.hotjar.com www.google.de us.i.posthog.com www.google-analytics.com script.hotjar.com js.hs-scripts.com www.google.com js.hsadspixel.net js.hs-banner.com js.usemessages.com js.hs-analytics.net js.hubspot.com js.hscollectedforms.net googleads.g.doubleclick.net browser.sentry-cdn.com; object-src 'self'; img-src 'self' 'unsafe-inline' data: images.ctfassets.net forms.hsforms.com *.hsforms.com perf-na1.hsforms.com dev.visualwebsiteoptim- strict-transport-security
max-age=31536000