mint.io
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
DNS records live
- NS
-
- anna.ns.cloudflare.com
- ray.ns.cloudflare.com
- MX
-
- 1 smtp.google.com
- TXT
-
linkedin-site-verification=5cdeaa39-7b2d-4451-b799-9b882b2f25b0linkedin-site-verification=15fa21ff-8191-47c9-b029-3182c9e0d91c
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsyeI7s1NiRnAAcgLcxzVw/jZmy0hn64PFaBgJk1ujaOyMgs62eXNfV9f6rYo4XTM32zyzm3AsKnWQ8… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArOyYFchJLFhrYelfgYCxogmN9AzQceoevaTYWIuPsNmi5Ov+JyL0HadeE9UvIwyc5QO59xGg6x6bK4jB7w… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDD1VaKOnp8NrIz2ZXWrEqne+QEC3kjfaKtu+EKU2tfPmUp1UZ2n3MvE9/B2GWFqlQwgrs/DDxWP9mgeEL6bPe7AV…
selectors probed - google:
Certificate (current)
E8
Expires in 35 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'nonce-MjE3NGEzOTUtMDQ1Ni00YzNkLThmN2EtYjQ1NWFmNDVlMzEz' 'strict-dynamic' wss://*.mint.io https://*.mint.io https://auth.privy.io https://*.googletagmanager.com https://*.google-analytics.com http://vercel.live https://*.sportbook.work wss://*.sportbook.work https://*.betby.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://livetracker.live https://*.btgpub.online wss://*.btgpub.online https://*.vdnsport.cc https://*.twitch.tv https://smdvks.live https://dmdvw.live https://beacon-v2.helpscout.net https://d3hb14vkzrxvla.cloudfront.net https://*.fullstory.com https://*.coconut-de.atservices-api.solutions wss://*.coconut-de.atservices-api.solutions; style-src 'self' 'unsafe-inline' https://*.sportbook.work wss://*.sportbook.work https://*.betby.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://livetracker.live https://*.btgpub.online wss://*.btgpub.online https://*.vdnsport.cc https://*.twitch.tv https://smdv- strict-transport-security
max-age=31536000; includeSubDomains; preload