maximeheckel.com

.com crawl

First seen 2026-04-13 · Last seen 2026-05-06 · ok HTTP/1.1 200 223 ms crawled 2026-05-06

US · 76.76.21.21 · AS16509 Amazon.com, Inc.

Reputation 97/100 dmarc monitor-only

Classifying

HTML metadata

Title
The online home of Maxime's work
Description
Hi! I'm Maxime, a frontend engineer based in New York. Welcome to my corner of the Internet, where I showcase my work, craft, unfinished or imperfect projects, and the many other things I'm exploring.
Language
en
Canonical
https://maximeheckel.com

Open Graph

url
https://maximeheckel.com
title
The online home of Maxime's work
description
Hi! I'm Maxime, a frontend engineer based in New York. Welcome to my corner of the Internet, where I showcase my work, craft, unfinished or imperfect projects, and the many other things I'm exploring.

Technology

CDN
Vercel
CMS
Next.js

Social

Contact

Address
st UpdatedMar 2025

Registration

Registrar
Cloudflare, Inc.
Created
2013-03-13
Expires
2027-03-13 298 days left
Updated
2025-01-19
Name servers
  • alaric.ns.cloudflare.com
  • carioca.ns.cloudflare.com

DNS records live

NS
  • alaric.ns.cloudflare.com
  • carioca.ns.cloudflare.com
MX
  • 29 route2.mx.cloudflare.net
  • 96 route3.mx.cloudflare.net
  • 99 route1.mx.cloudflare.net

Email authentication strong

SPF
v=spf1 include:_spf.mx.cloudflare.net include:_spf.google.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:a5884eb41ef343599069c55bde887644@dmarc-reports.cloudflare.net
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-17 to 2026-07-16
Expires in 58 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://maximeheckel.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
origin-when-cross-origin
x-frame-options
DENY
permissions-policy
camera=(), microphone=(), geolocation=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' data:; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.youtube.com *.twitter.com; child-src *.youtube.com *.vimeo.com *.google.com *.twitter.com *.codesandbox.io; style-src 'self' 'unsafe-inline' *.googleapis.com; img-src * blob: data:; media-src 'self' cdn.maximeheckel.com https://video.twimg.com; connect-src *; font-src 'self'; worker-src blob:;
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (6)

Linked from (2)