lanza.me
HTML metadata
Technology
- Server
- Heroku
- jQuery
- 3.4.1 known XSS (<3.5)
- Fonts
-
- Google Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (5)
- cdnjs.cloudflare.com×2
- code.jquery.com×1
- fonts.googleapis.com×1
- maxcdn.bootstrapcdn.com×1
- www.youtube.com×1
DNS records live
- NS
-
- graham.ns.cloudflare.com
- jillian.ns.cloudflare.com
- MX
-
- 10 mx1.forwardemail.net
- 10 mx2.forwardemail.net
- TXT
-
forward-email=jorge.vr06@gmail.com
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 include:spf.efwd.registrar-servers.com include:spf.ipzmarketing.com include:spf.mailjet.com a mx ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 56 days
HTTP security headers
- present
-
- strict-transport-security
- x-content-type-options
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- missing Content Security Policy
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin