hover.com
HTML metadata
Technology
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- hover-assets.s3.ca-central-1.amazonaws.com×21
- fonts.googleapis.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 1996-07-12
- Expires
- 2026-07-11 52 days left
- Updated
- 2025-06-12
- Name servers
-
- ns1.tucows.com
- ns2.tucows.com
- ns3.tucows.com
DNS records live
- NS
-
- ns1.tucows.com
- ns2.tucows.com
- ns3.tucows.com
- MX
-
- 10 mx.hover.com.cust.hostedemail.com
- TXT
-
google-site-verification=7Gcxj0XHOF00PQjd4sKDkSnlHABhEj596GrvVAti2PMyahoo-verification-key=YwRDeKoXWpjp3ge0iRPEEfsl1is5M7U/pdAWrH1C7l0=
Email authentication partial
- SPF
-
v=spf1 include:_spf.hostedemail.com include:support.zendesk.com include:servers.mcsv.net include:mail.zendesk.com include:registrarmail.net include:_spf.emfwd.name-services.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-rua@abuse.tucows.com; ruf=mailto:dmarc-ruf@abuse.tucows.com; fo=0; adkim=r; aspf=r; pct=100; rf=afrf; ri=86400; sp=nonepolicy: none (monitoring only) · sp=none - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
R12
Expires in 79 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:; font-src 'self' https://hover-assets.s3.ca-central-1.amazonaws.com/ https://s3.ca-central-1.amazonaws.com/hover-assets/ https://fonts.gstatic.com/ https://p1.answerdash.com/ https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://hover-assets.s3.ca-central-1.amazonaws.com/ https://s3.ca-central-1.amazonaws.com/hover-assets/ https://*.paypal.com/ https://www.facebook.com/ https://connect.facebook.net/ https://www.linkedin.com/ https://px.ads.linkedin.com/ https://px4.ads.linkedin.com https://chart.googleapis.com/ https://www.google.com/ https://www.google.ca/ https://*.google-analytics.com/ https://*.googletagmanager.com/ https://*.zopim.io/ https://api.smooch.io/ https://hover.zendesk.com/ https://*.licdn.com/ https://*.hsforms.net/ https://*.hsforms.com/; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ad.doubleclick.net/ https://hover-assets.s3.ca-central-1.amazonaws.com/ https://s3.ca-central-1.amazonaws.com/hover-assets/- strict-transport-security
max-age=63072000; includeSubDomains; preload