lumion.com

.com crawl

First seen 2026-06-01 · Last seen 2026-06-01 · ok HTTP/1.1 200 390 ms crawled 2026-06-02

US · 104.18.20.212 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Lumion | Industry-Leading 3D Rendering Software For Architects - Lumion 3D Rendering Software for Architects
Description
Transform your design workflow with Lumion’s powerful real-time rendering software. From concept to final render, visualize every step with speed, quality, and ease.
Language
en
Canonical
https://lumion.com/
Translations
  • de
  • en

Open Graph

url
https://lumion.com/
title
Lumion | Industry-Leading 3D Rendering Software For Architects - Lumion 3D Rendering Software for Architects
locale
en
site name
Lumion
description
Transform your design workflow with Lumion’s powerful real-time rendering software. From concept to final render, visualize every step with speed, quality, and ease.

Technology

CDN
Cloudflare
CMS
Next.js
JS framework
Next.js
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Registration

Registrar
Cloudflare, Inc.
Created
2002-11-27
Expires
2026-09-08 97 days left
Updated
2024-02-20
Name servers
  • sam.ns.cloudflare.com
  • zoe.ns.cloudflare.com

DNS records live

NS
  • sam.ns.cloudflare.com
  • zoe.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • 1st9tz7hg289avmvwdgw6pb1nd
  • a7a28e07hn2fpgmickr08f9kjr
Verified for
  • 1Password
  • Google
  • Meta
  • Microsoft 365

Email authentication partial

SPF
v=spf1 ip4:65.52.128.33 ip4:217.67.236.38 ip4:168.245.12.151 mx include:spf.mandrillapp.com include:mail.zendesk.com include:_spf.google.com include:25757866.spf01.hubspotemail.net -all
strict (-all)
DMARC
v=DMARC1; p=none; sp=none; rua=mailto:dmarc-reporting@lumion.com; ruf=mailto:dmarc-reporting@lumion.com;
policy: none (monitoring only) · sp=none
DKIM
Show 4 DKIM selectors
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuVsVnJhvL4xM/OOxGObewqrcpSJnTAFiwb3nS/8ZCSbQvTMieB389SXMRZBDz7Y3FO0WDFwY4BfP3M…
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqv3ndQmo1JQxaKhwYn8OrRLcpjicHnsoKzGD7wIccR/+hl97p2p/VnbKI67QCbLQKoZLf7HpXj0mZbmSEQ…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDK7H30TWCdjNIOm3jFezGgpCpC3+Y/mfa8ch1QezEz+88/wk5LdhpMqm+dRBYZ2xdaPahN2hsTtnslLKAX8arsNV…
selectors probed

Certificate (current)

WE1
from 2026-04-24 to 2026-07-23
Expires in 51 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://lumion.com/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
default-src http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval' data: https: service-content.lumion.com services.lumion3d.net lumion.com s.ytimg.com www.youtube.com www.youtube-nocookie.com kit.fontawesome.com kit-free.fontaw.com ajax.googleapis.com fonts.googleapis.com use.typekit.net p.typekit.net use.fontawesome.com t.co ipapi.co www.google-analytics.com www.googleadservices.com connect.facebook.net static.ads-twitter.com analytics.twitter.com platform.twitter.com cdn.syndication.twimg.com static.hotjar.com script.hotjar.com vars.hotjar.com in.hotjar.com vc.hotjar.io www.google.com www.facebook.com fonts.gstatic.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ www.googletagmanager.com static.cloudflareinsights.com ajax.cloudflare.com api.iconify.design https://*.sheerid.com platform.twitter.com https://js.hsforms.net https://js-eu1.hsforms.net; frame-ancestors 'self' https
strict-transport-security
max-age=63072000; includeSubDomains; preload

Linked from (2)