mybid.io
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- api.s.mindbox.ru×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- dns1.mybid.io
- dns2.mybid.io
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 5 TXT records
google-site-verification=EZ7VyFJ8SIJFQEjGKYv0K5Ck18SsHudvxFdTAqdlBfsgoogle-site-verification=pHe--6bTj1FYzKzB3IHCW0MbHlEACHnLtnfVDDrAnz0slack-domain-verification=qBqqMFwJxrSmtxk8zNwAudqye1UplXLF5VwjlC0qv=spf1 include:_spf.google.com ~allgoogle-site-verification=Q17MrOZ_jkInDBpbCFL_nlyXSqHgBvJpGuOTf2mEClI
Certificate (current)
R13
Expires in 66 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
geolocation=(), camera=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval' 'unsafe-dynamic'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src * data: blob: 'unsafe-inline'; img-src * data: blob:; connect-src * data: blob:; frame-src * data: blob:; font-src * data: blob:; media-src * data: blob:; object-src 'none'; base-uri *; form-action *; frame-ancestors *;- strict-transport-security
max-age=31536000; includeSubDomains
Links to (4)
- facebook.com×2
- instagram.com×2
- linkedin.com×2
- t.me×2