monami.io
HTML metadata
Technology
- CMS
- Gatsby
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Google Ads
- Google Ads (DoubleClick)
Third-party hosts loaded (9)
- draff458giw8a.cloudfront.net×48
- googleads.g.doubleclick.net×1
- js.honeybadger.io×1
- js.hs-scripts.com×1
- monami-images-production.s3.us-east-2.amazonaws.com×1
- stats.g.doubleclick.net×1
- www.google-analytics.com×1
- www.googleadservices.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns-1415.awsdns-48.org
- ns-1660.awsdns-15.co.uk
- ns-250.awsdns-31.com
- ns-550.awsdns-04.net
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
anthropic-domain-verification-0d87yf=u5uFcYEa1ez2jrURJrtbekrxxgoogle-site-verification=lohwBYyVqkby-6h_HuBozEDvY0aj9QrcP59Wbm2Vpmoairtable-verification=bbfac36d5a75aee4ec7d2b5c5ce4a60c
Email authentication partial
- SPF
-
v=spf1 include:_spf.mlsend.com include:_spf.google.com ip4:149.72.175.45 include:21350726.spf07.hubspotemail.net include:mail.zendesk.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-aggregates@monami.io; ruf=mailto:dmarc-forensics@monami.io; fo=1policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmOzsoSFcdMBWCv2nb4OET+F9DfD+xGR+lIu6q5ja5FskKKlvi9rgMwBJVAnulIOkKl6/ejDhLtvkxZ… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw1yBG3K/M/lAfMKgNL39VVPDxMF0uqKj0oArloJIuSjt0BuLaulSKf6cwU+lzh2HILHqvdsFYoOJqpXnhr… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCuydTvD31bmLwvh+gqeyvSlPKrPx/SZIOcEiNMxZCuKPrtm8UB3PP/RIb4E3HqMl7nrIopUmKXpXT6ZE/dJPJjxn…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 217 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing Content Security Policy
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- strict-transport-security
max-age=63072000; includeSubDomains- content-security-policy-report-only
script-src 'self' https: 'unsafe-eval' 'unsafe-inline' 'strict-dynamic' https://*.heapanalytics.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net 'nonce-57e6b54a924d48b30e5566a769ce9361'; script-src-elem 'self' https: 'unsafe-eval' 'unsafe-inline' 'strict-dynamic' https://*.heapanalytics.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net; style-src 'self' https: 'unsafe-eval' 'unsafe-inline' 'nonce-57e6b54a924d48b30e5566a769ce9361'; style-src-elem 'self' https: 'unsafe-eval' 'unsafe-inline' https://*.zdassets.com https://monamisupport.zendesk.com; connect-src 'self' https: https://monamisupport.zendesk.com wss://*.zendesk.com wss://widget-mediator.zopim.com https://id.zopim.com https://cdn.heapanalytics.com https://heapanalytics.com https://*.auryc.com https://embed.oneschema.co; font-src 'self' https: data:; child-src 'self' blob: https://js.stripe.com https://www.youtube.com https://player.vimeo.