kryll.io
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
Third-party hosts loaded (2)
- www.googletagmanager.com×2
- static.cloudflareinsights.com×1
Social
Contact
DNS records live
- NS
-
- brad.ns.cloudflare.com
- karina.ns.cloudflare.com
- MX
-
- 10 spool.mail.gandi.net
- 50 fb.mail.gandi.net
- TXT
-
Show 6 TXT records
brevo-code:2146eed7ea71b5fcec19f514cf76e53dgoogle-site-verification=Ydpx2njQ6Vadhaj6YxbD5fWFBBVe147tvjrfwUSoWoEgoogle-site-verification=zJYJ4LhMbKsFKazdJvWiHHRucW51_GS_MoMgbHlpFpMv=spf1 mx ip4:213.32.175.62 ip4:168.245.92.225 ip4:51.159.22.41 include:_mailcust.gandi.net include:spf.sendinblue.com include:_spf.google.com -all67b1526c-d01e-4e49-92ba-4f333822b60c=caaaa3f2305bd3a3de281f38221a134331b61acad29d2bd8163a214134464351brave-ledger-verification=15f881742a03dfa9f2cc6e35f981d7997fe89a9e04fc697164ace293d186a3e0
Certificate (current)
WE1
Expires in 58 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
document-domain=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'nonce-Z4s7Qh9p' *.kryll.io *.googleapis.com *.cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.google-analytics.com cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com dev.visualwebsiteoptimizer.com crypto.com; style-src 'self' 'unsafe-inline' *.kryll.io cdn.jsdelivr.net cdnjs.cloudflare.com *.googleapis.com animaproject.s3.amazonaws.com px.animaapp.com; font-src 'self' cdnjs.cloudflare.com cdn.jsdelivr.net *.kryll.io *.googleapis.com fonts.gstatic.com; connect-src 'self' *.kryll.io *.google-analytics.com analytics.google.com *.analytics.google.com stats.g.doubleclick.net api.coingecko.com cloudflareinsights.com *.zendesk.com *.zdassets.com; object-src 'none'; img-src 'self' data: *;- strict-transport-security
max-age=15552000