nothing.tech
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Shopify
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (5)
- cdn.shopify.com×67
- cdn.sanity.io×6
- shop.app×1
- www.facebook.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- dalary.ns.cloudflare.com
- vicente.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 8 TXT records
google-site-verification=DccVkg9e-bx98J8gN-V1vCHpbVcvvrBz-vE95w6mifkgoogle-site-verification=HEg0R1mBjmehzEwsZ8dQGfhqD1DH7HxahbhquHTKhf4google-site-verification=HciXLWEOtbFXRikRaPI1XGLxHxDMwyl1cvSOuU6KE90google-site-verification=je2HKKDRhKzQuOExqg3UlThprS6skyB7kM3TqbGcldMgoogle-site-verification=mtyR9J-gp8xFgMRPw6I1asf1-6uQ3Djh_RhoLzUPUwoklaviyo-site-verification=XDhrgNslack-domain-verification=guLgycwXUyj5tULZ0WhHnwSoaWCeLFyt3WpqZrekatlassian-domain-verification=afrb7uHD9matsgC2L7NUpK8Iqlq2tAicMIksDdsHcjnfGwfvNcDI5IajnDQGvsGx
Email authentication partial
- SPF
-
v=spf1 ip4:103.73.96.160/30 ip4:183.62.97.146/29 include:_spf.google.com include:mail.zendesk.com include:sendgrid.net include:larksuite.com include:shops.shopify.com include:spf.emea.sykes.com include:servers.mcsv.n include:ptr.blmpb.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:postmaster@nothing.tech, mailto:info@shopline.com, mailto:6979ea4fe5002@ag.dmarcly.com; ruf=mailto:info@shopline.com,mailto:6979ea4fe5002@fo.dmarcly.com; rf=afrf; pct=100; sp=nonepolicy: none (monitoring only) · sp=none - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4/F7DS5Bh2sEcPWJoQRpfR7kwbWkmkFAmcexhism2AZkfmbOM70J90lMGIehwU4EQNS2aRQ7aGxRYu… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu8797GQHaJELFgmCciDbNJY/D+Yann7wGVOZABQUdioiTZY3n4Uqtl+j83OQZ0uwk3tKvNKTicWxtR+Z1d… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2t4OpQp3clLForK/W0s06kliB3dVk36N59F5tK2pjRWnwSqUJoSnyRcKWIoym8VYL4xDO9kJYt9yenkREI…
selectors probed - google:
Certificate (current)
E7
Expires in 45 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src https://cdn.sanity.io https://static.zdassets.com https://api.smooch.io https://ajax.googleapis.com https://static.klaviyo.com https://*.shopify.com https://cdn.shopifycdn.net https://*.googletagmanager.com https://analytics.tiktok.com 'self' 'nonce-96256df02579048f79322703a1f8f76f' https://cdn.shopify.com https://shopify.com; frame-ancestors; style-src 'self' 'unsafe-inline' https://cdn.shopify.com https://cdn.shopifycdn.net https://fonts.googleapis.com https://*.googletagmanager.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src https://cdn.sanity.io https://nothingtechsupport.zendesk.com https://nothingtechsupporteu.zendesk.com https://ekr.zdassets.com wss://api.smooch.io blob: https://*.google-analytics.com https://*.googletagmanager.com https://www.googleadservices.com https://analytics.google.com https://*.analytics.google.com https://google.com https://www.google.com https://*.google.co.uk https://*.googleadservices.com https://analytics- strict-transport-security
max-age=31536000