lumen5.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- storage.googleapis.com×31
- fonts.googleapis.com×2
- www.googletagmanager.com×2
- js.hs-scripts.com×1
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2016-11-03
- Expires
- 2026-11-03 167 days left
- Updated
- 2025-10-04
- Name servers
-
- alice.ns.cloudflare.com
- justin.ns.cloudflare.com
DNS records live
- NS
-
- alice.ns.cloudflare.com
- justin.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 7 TXT records
apple-domain-verification=yFefs8BA7xpYsJcQdetectify-verification=64176da2d23db798c17d5c1d00fa882agoogle-site-verification=4azvRjyJY4yj9ByRqc6yxZ1_d1ok6HUibSrt0UWUf6ggoogle-site-verification=AylHvATtdFb-lolGYganNk_FjW7FlvCxMEhr_93CP5wgoogle-site-verification=Jb9zFmi2d8h2F12aCXybWq3JEmcm-tIwY7aQOFGXSmogoogle-site-verification=iAIvO3sxmTIKHuqtLiRwL1qfrLR2w14wtJeluG1ixj4MS=ms25425252
Email authentication strong
- SPF
-
v=spf1 include:sendgrid.net include:_spf.google.com include:4012735.spf07.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:re+g21n7jqqlqv@dmarc.postmarkapp.com; sp=reject; aspf=r;policy: reject (enforced) · sp=reject - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4/gRaotJHfkJjWgngJSWF6G8eDajH4FcSdpYzVabqAEcRP1WT065nL9DXaNf/r9NY+Yfk280WcnlhK3QPy… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCuF6KRfxiko50Paok/OvD+p56koZvofcx7bnWixRVZpFsqAYlhnqob7kKCI26IgpDo8b1pLBDnvSWqVB21L7Lm0K…
selectors probed - s1:
Certificate (current)
WE1
Expires in 21 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(self)- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-eval' blob: wss: ws: https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://cdn4.mxpnl.com https://client.crisp.chat https://js.hs-scripts.com https://js.hsforms.net https://js.hs-analytics.net https://static.hsappstatic.net https://js.hubspot.com https://js.hsadspixel.net https://js.hs-banner.com https://js.zi-scripts.com https://baremetrics-dunning.baremetrics.com https://boards.greenhouse.io https://connect.facebook.net https://js.stripe.com https://cdnjs.cloudflare.com https://storage.googleapis.com https://challenges.cloudflare.com 'nonce-KjxhdaKtzun4fimxK9kdfw=='; style-src * 'self' https: 'unsafe-inline'; form-action 'self' https://www.facebook.com; font-src 'self' https: blob: data:; media-src * blob: data:; frame-ancestors 'none'; base-uri 'self'; default-src 'self' 'unsafe-eval' https: blob: ws: wss:; object-src 'self'; img-src * blob: data:; report-uri https://o4- strict-transport-security
max-age=2592000- cross-origin-opener-policy
same-origin