hyperfixedpod.com
HTML metadata
Technology
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- media.supportingcast.fm×7
- f.prxu.org×4
- embed.typeform.com×1
- fonts.googleapis.com×1
- www.google.com×1
- www.gstatic.com×1
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2024-06-21
- Expires
- 2026-06-21 32 days left
- Updated
- 2025-06-06
- Name servers
-
- dns1.registrar-servers.com
- dns2.registrar-servers.com
DNS records live
- NS
-
- dns1.registrar-servers.com
- dns2.registrar-servers.com
- MX
-
- 10 mx1.privateemail.com
- 10 mx2.privateemail.com
- TXT
-
Value: v=spf1 include:spf.privateemail.com ~all
Email authentication weak
- SPF
- not published
- DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- default:
v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoR/B3HoIpV2M84RvBx/nq4gzLQ2Ed0nneRfKt4skmI55natHH8SSFhwHWtXc6QJP9ejbri/ra97hXf2C… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - default:
Certificate (current)
Certainly Intermediate R1
Expires in 24 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
DENY- permissions-policy
camera=(), display-capture=(self), fullscreen=(self), geolocation=(), microphone=(), web-share=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' api.npr.org *.amplitude.com cdn.jsdelivr.net *.litix.io *.mux.com *.stripe.com www.google.com *.google-analytics.com *.googleapis.com *.gstatic.com cdnjs.cloudflare.com *.googletagmanager.com *.facebook.net *.facebook.com *.mouseflow.com polyfill-fastly.io embed.typeform.com api.typeform.com form.typeform.com *.youtube.com soundcloud.com *.supportingcast.fm www.hyperfixedpod.com supportingcast.s3.amazonaws.com sc-uploads-prod.s3.amazonaws.com sc-uploads-prod.s3-accelerate.amazonaws.com data:;form-action *.supportingcast.fm www.hyperfixedpod.com docs.google.com connect.stripe.com *.supportingcast.fm;img-src * data:;media-src * data: blob:;worker-src blob:;connect-src 'self' api.npr.org *.amplitude.com cdn.jsdelivr.net *.litix.io *.mux.com *.stripe.com www.google.com *.google-analytics.com *.googleapis.com *.gstatic.com cdnjs.cloudflare.com *.googletagmanager.com *.facebook.net *.facebook.com *.mouseflow.com polyfill-fastly.io embed.typeform.com api.typeform.com form- strict-transport-security
max-age=31536000; includeSubDomains