mynd.co
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Segment
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- images.ctfassets.net×15
- fonts.gstatic.com×4
- cdn.segment.com×1
Social
DNS records live
- NS
-
- ns-130.awsdns-16.com
- ns-1318.awsdns-36.org
- ns-1716.awsdns-22.co.uk
- ns-855.awsdns-42.net
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 20 TXT records
00D41000000fTgn=1TBUL00000002Jalogmein-verification-code=78dcaa85-028f-4bc3-b6f0-f156e9e69e04dropbox-domain-verification=d5265jgj0x8cdocusign=f2a4fe5d-82c8-4cc6-8d0a-9d43d19c9b4fZOOM_verify_yIf3YSaXRCWIkbu5z-Svjwairtable-verification=adfb94b3fffe1b75d4709a70463cc1d3notion-domain-verification=FDVrCfmspYHr5eQW3yEK5CQmfuLIlPIanyU11e0tMZxsegment-site-verification=kbRGurbiItX2T2sgK5NhOD6CufOgn41wMS=ms84591726smartsheet-site-validation=kq8I-SoZnH8L8zt16s7zdaaGGYKto-ZbMS=ms863719487330D30613google-site-verification=zDIOaLtsOzfGwh3xjx3or_u1fCFvh3FMa8OV9VVrobkapple-domain-verification=RNhQU9RKvvAewpa7anthropic-domain-verification-gpkxva=fXGJzcScsGdTJRzhnLs6BK0Yhatlassian-domain-verification=NlpP4vLUR5RKzqUFiAyIS3kNVNKrhlZcQbPNAnJp1sPxVKIME78gEgv3/kDaA1xTfigma-domain-verification=653d8b94272571233fbe83b3199cc205c4b805963c1b4d960072a7e3ac71abdb-1726864056slack-domain-verification=1fA8JSEfCEBmN2ueJ3wxituMqjuZdHTDGDhXwACwadobe-idp-site-verification=3f1fc87d4d9156a62901dacb683e14157fd5b7a23a9ee325b5e064b10530a669ZOOM_verify_UIjEwldd5rbdMTPTT8EvEG
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:sendgrid.net include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;pct=100;ruf=mailto:615b1bf6@forensics.dmarc-report.com,mailto:spoofing@mynd.co; rua=mailto:615b1bf6@mxtoolbox.dmarc-report.compolicy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC/Yc0D1XdbFIHfGAHgQMZmKACLmfXxut0JkUulVgTRm1ZhIkyEW+CO5/SA/r07F4j81aT0BrtwXv9P+fb9dh… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnzha9QD4uoxsuKk+ZYILnKfeI72pe1iEWNoMir9k6eR1JYbLi56O8TcwCNAyFu8ULMYZ+OIrkG7sUb7wJ0… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCg1PRWbltRFs8KpfIiXec/Tzod+a2hqUhfonRY0F9ijtkcMXauT+HHuRmCUH44eqOyDtkE5a1rrfH/PwucDlc8Qh…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 161 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:;- strict-transport-security
max-age=31536000; includeSubDomains
Links to (9)
- facebook.com×2
- google.com×2
- instagram.com×2
- ivesins.com×2
- linkedin.com×2
- rhenti.com×2
- stonly.com×2
- twitter.com×2
- youtube.com×2