kiplearn.co
HTML metadata
Technology
Third-party hosts loaded (1)
- js.stripe.com×1
DNS records live
- NS
-
- ns-1469.awsdns-55.org
- ns-1738.awsdns-25.co.uk
- ns-413.awsdns-51.com
- ns-919.awsdns-50.net
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificates
Loading certificate
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self' blob: 'unsafe-inline' https://*.kiplearn.co https://auth.kiplearn.co https://*.blob.core.windows.net;frame-src 'self' blob: https://*.kiplearn.co https://*.kipmcgrath.com https://*.kipmcgrath.com.au https://*.kipmcgrath.co.uk https://*.kipmcgrath.dev data: https://player.vimeo.com https://kiplearn.readyplayer.me https://js.stripe.com https://hooks.stripe.com;object-src 'none';connect-src 'self' blob: data: ws: wss: https://*.kiplearn.co https://auth.kiplearn.co https://*.kipmcgrath.com https://*.kipmcgrath.com.au https://*.kipmcgrath.co.uk https://*.kipmcgrath.dev https://*.googleapis.com https://*.google-analytics.com https://texttospeech.googleapis.com https://*.readyplayer.me https://*.service.signalr.net https://*.tokbox.com https://*.opentok.com https://api.stripe.com https://sentry.io https://*.sentry.io https://d2f9wo3x2pufsw.cloudfront.net https://*.blob.core.windows.net https://d1nv5i00u1m742.cloudfront.net https://tnaquic5o3.execute-api.ap-southeast-2.amazo- strict-transport-security
max-age=15724800; includeSubDomains