marcopolo.me
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Nuxt
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- transcend-cdn.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns-1497.awsdns-59.org
- ns-1676.awsdns-17.co.uk
- ns-354.awsdns-44.com
- ns-562.awsdns-06.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
facebook-domain-verification=ggbruea8ya84skhi4ezoqqtjza8o6kgoogle-site-verification=Inc6tbXkq45WPyC2y2EcIpum8wyvhXlI-5SdlU9hZnMgoogle-site-verification=mP4dj4C_8WcEzzMjRiZqMWE09ZHFgsOYetGrk536llsgoogle-site-verification=mnqMR7Ack1HRhtkKVbCNN8k06RLlyJt2br8TLzUacTEgoogle-site-verification=rlk72oK6Q94fCIfnZ832pmkzeMIYI2MVbuOFexLfn2kcursor-domain-verification-s0s7cs=Nuj7Grp2pCXsatyRtFcksDQGL
Email authentication strong
- SPF
-
v=spf1 include:servers.mcsv.net include:helpscoutemail.com include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:re+ibp3zbggljq@dmarc.postmarkapp.com,mailto:postmaster@marcopolo.me;policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAiQXDbyc8G5FU9t3EcWxG0YqBZlk9aRKasQzZGxO3N68j9c3SvLrZCJ2oVPr0zeL+47rOyJ098ZqQI4… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 205 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; font-src 'self' https: data:; form-action 'self'; frame-ancestors 'self' https://plugins-cdn.datocms.com https://marco-polo-business-blog.admin.datocms.com; img-src 'self' data: https://www.datocms-assets.com https://i.ytimg.com https://image.mux.com https://*.googletagmanager.com https://*.google-analytics.com; object-src 'none'; script-src-attr 'none'; style-src 'self' https: 'unsafe-inline'; script-src 'self' https: 'unsafe-inline' 'strict-dynamic' 'nonce-yu9551PxK976UF0mubsG5oPY' 'wasm-unsafe-eval'; upgrade-insecure-requests; connect-src 'self' https://*.marcopolo.me https://*.amplitude.com https://*.sentry.io https://*.google-analytics.com https://*.googletagmanager.com https://transcend-cdn.com https://*.transcend.io https://www.getjoya.com; frame-src https://www.youtube.com https://embed.podcasts.apple.com https://open.spotify.com https://w.soundcloud.com https://www.buzzsprout.com;- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin