medplum.com
HTML metadata
Technology
- CDN
- Vercel
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (3)
- www.googletagmanager.com×2
- 6a1dxs603n-dsn.algolia.net×1
- www.google-analytics.com×1
Social
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2015-04-25
- Expires
- 2027-04-25 340 days left
- Updated
- 2026-03-21
- Name servers
-
- ns-1255.awsdns-28.org
- ns-1541.awsdns-00.co.uk
- ns-358.awsdns-44.com
- ns-991.awsdns-59.net
DNS records live
- NS
-
- ns-1255.awsdns-28.org
- ns-1541.awsdns-00.co.uk
- ns-358.awsdns-44.com
- ns-991.awsdns-59.net
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
ahrefs-site-verification_ca089e80efeb956aec324357e1083e97b6a9a6227d37483ac69d071070edab5dgoogle-site-verification=q2-ubkKemCq4952ofpugXvktau5dKilSgZbYuj6CIPk
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:_spf.paubox.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:1e9a43b67024.a@dmarcinput.com,mailto:dmarc@medplum.com; ruf=mailto:1e9a43b67024.f@dmarcinput.com; fo=1policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC21diNSyc82hCJuJJBG7tI4fyO8fYDU2Zk8FaiaBFOER0GuaKZwhpI9uLCP6ImhdLD214DXGUZt1MEaFo0lH… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - google:
Certificate (current)
R12
Expires in 35 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; base-uri 'self'; child-src 'self'; connect-src 'self' *.medplum.com *.google.com *.google-analytics.com *.algolia.net vercel.live; font-src 'self' data: fonts.gstatic.com assets.vercel.com; form-action 'self' *.gstatic.com *.google.com; frame-ancestors 'self' *.medplum.com; frame-src 'self' *.medplum.com *.gstatic.com *.google.com *.youtube.com vercel.live; img-src 'self' data: *.medplum.com *.gstatic.com *.google.com *.googletagmanager.com github.com *.github.com *.githubusercontent.com *.youtube.com vercel.com assets.vercel.com; manifest-src 'self'; media-src 'self' *.medplum.com; script-src 'self' 'unsafe-inline' *.medplum.com *.gstatic.com *.google.com *.googleapis.com *.googletagmanager.com vercel.live; style-src 'self' 'unsafe-inline' *.medplum.com *.gstatic.com *.google.com *.googleapis.com; worker-src 'self' blob: *.medplum.com *.gstatic.com *.google.com; upgrade-insecure-requests- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (2)
- cal.com×1
- github.com×1