habitsofmindinstitute.org

.org crawl

First seen 2026-05-03 · Last seen 2026-05-03 · ok HTTP/1.1 200 977 ms crawled 2026-05-10

DE · 63.176.8.218 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
The Institute for Habits of Mind
Language
en

Technology

CDN
Netlify

Registration

Registrar
Tucows Domains Inc.
Created
2013-12-17
Expires
2026-12-17 211 days left
Updated
2025-09-26
Name servers
  • dns1.p05.nsone.net
  • dns2.p05.nsone.net
  • dns3.p05.nsone.net
  • dns4.p05.nsone.net

DNS records live

NS
  • dns1.p05.nsone.net
  • dns2.p05.nsone.net
  • dns3.p05.nsone.net
  • dns4.p05.nsone.net
MX
  • 10 mx10.antispam.mailspamprotection.com
  • 20 mx20.antispam.mailspamprotection.com
  • 30 mx30.antispam.mailspamprotection.com

Email authentication weak

SPF
v=spf1 +a +mx include:_spf.mailspamprotection.com include:convertkit.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

E8
from 2026-03-23 to 2026-06-21
Expires in 33 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://habitsofmindinstitute.org/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.auth0.com https://*.auth0.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://*.google-analytics.com https://cdn.tiny.cloud https://apis.google.com https://*.sentry.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.tiny.cloud; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https: blob:; media-src 'self' blob:; connect-src 'self' https://habits-of-mind-backend-251762ec444d.herokuapp.com https://*.auth0.com https://api.openai.com https://*.googleapis.com https://*.google.com https://*.firebaseapp.com https://*.cloudfunctions.net https://www.google-analytics.com https://*.google-analytics.com https://*.googletagmanager.com https://cdn.tiny.cloud https://accounts.google.com https://calendar.google.com https://*.sentry.io https://*.ingest.sentry.io; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-src 'self'
strict-transport-security
max-age=31536000

Linked from (1)