interiordefine.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- Analytics
-
- Google Analytics
- Ads
-
- Google Ads (DoubleClick)
- Fonts
-
- Adobe Fonts
- Google Fonts
Third-party hosts loaded (9)
- content.cylindo.com×1
- embed-cloudfront.wistia.com×1
- embed-ssl.wistia.com×1
- fast.wistia.com×1
- fonts.googleapis.com×1
- orbit.havenly.com×1
- stats.g.doubleclick.net×1
- use.typekit.net×1
- www.google-analytics.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2008-08-25
- Expires
- 2027-08-25 462 days left
- Updated
- 2022-09-14
- Name servers
-
- ns-1031.awsdns-00.org
- ns-1567.awsdns-03.co.uk
- ns-359.awsdns-44.com
- ns-764.awsdns-31.net
DNS records live
- NS
-
- ns-1031.awsdns-00.org
- ns-1567.awsdns-03.co.uk
- ns-359.awsdns-44.com
- ns-764.awsdns-31.net
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 30 alt2.aspmx.l.google.com
- 40 aspmx2.googlemail.com
- 50 aspmx3.googlemail.com
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:servers.mcsv.net include:sendgrid.net include:spf.mandrillapp.com include:23765919.spf05.hubspotemail.net include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:dmarc-reports@interiordefine.com,mailto:emailadmin@interiordefine.com; ruf=mailto:dmarc-failures@interiordefine.com; sp=reject; aspf=rpolicy: reject (enforced) · sp=reject - DKIM
-
Show 5 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvkjMctaFMDzh2LzEq3kt0GV2qeLQBBW6uClB7fHjfOf6VbRbI0pQSy/T97Mh05NG4RPvu28BZQadZG… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsp0xtC6nDQaN5oLdNYzZKIJeqaRqUmqgYvbOMSO0E3iKIZ7EPLy+K6TpBiZCidT4vy3vpZhDZs8nNwzjGi… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDLpoBIxPmHlFInccypbRnBLeS9tRqqCmrfrnY05EHwUBGKbzea+neKzmWPb+uPL2qurLd5L+JZdz7t83MH1p8UJs… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - google:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 45 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'unsafe-inline' 'unsafe-eval' http: https: http://nginx-svc:8000/ *.affirm.com interiordefine.secure.force.com https://cdn.heapanalytics.com https://heapanalytics.com https://assets.calendly.com *.getmulberry.com widget.fbot.me static.fbot.me *.pbbl.co *.attn.tv *.rewardStyle.com *.collect.igodigital.com analytics.tiktok.com interiordefine.my.salesforce.com www.googleadservices.com script.hotjar.com s.pinimg.com www.gstatic.com *.visualwebsiteoptimizer.com app.vwo.com *.hubspot.com js.hs-scripts.com js.hs-analytics.net js.usemessages.com web.chtbl.com *.pepperjamnetwork.com; style-src 'self' blob: https: 'unsafe-inline' http://nginx-svc:8000/ *.affirm.com cdn.pbbl.co/* https://heapanalytics.com widget.fbot.me static.fbot.me *.visualwebsiteoptimizer.com app.vwo.com s3.amazonaws.com *.pepperjamnetwork.com; img-src 'self' data: blob: http: https: https://heapanalytics.com *.rlcdn.com/* s.pinimg.com *.visualwebsiteoptimizer.com chart.googleapis.com wingify-assets.s3.amazonaws.co- strict-transport-security
max-age=31536000