notta.ai
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- CMS
- Gatsby
- Analytics
-
- Google Analytics
- Google Tag Manager
- Cookie consent
-
- Cookiebot
- Fonts
-
- Google Fonts
Third-party hosts loaded (9)
- a.storyblok.com×3
- fonts.gstatic.com×2
- www.googletagmanager.com×2
- assets.endorsely.com×1
- consent.cookiebot.com×1
- fonts.googleapis.com×1
- unpkg.com×1
- www.google-analytics.com×1
- www.youtube.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2020-01-16
- Expires
- 2028-01-16 605 days left
- Updated
- 2026-03-02
- Name servers
-
- ns-1964.awsdns-53.co.uk
- ns-562.awsdns-06.net
- ns-251.awsdns-31.com
- ns-1196.awsdns-21.org
DNS records live
- NS
-
- ns-1196.awsdns-21.org
- ns-1964.awsdns-53.co.uk
- ns-251.awsdns-31.com
- ns-562.awsdns-06.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 8 TXT records
eZQIiMpWp+74bz/RcK84bnBV38C9pyzh3pcb0jq/hGA=RLRRn//w1geR08jGJgyog7T16z7Xz73vWasMh+kJKBM=hubspot-developer-verification=MTQ2NDE0MTUtOGIwNS00MDY3LWEzZjMtOTEzM2QyOGQ2OWZl202104060212512j726ng945ly7l777z1g9aa7uq1tbtqatzg8hex8fv3oo2nyiuwork-os-domain-verification-w3cdsj=bK3L91BkqGOxOzAgQN0iIaBJSklaviyo-site-verification=WiPXNJqdn3A/0b3C7ZnbTETEW6OSMEdUcmefEAzbgD9+vrFOQ=workos-domain-verification=6ff317c3ba8f3ecf60020da5832469b7d3303b26
- Verified for
-
- Brevo
- Microsoft 365
- Notion
- Stripe
Email authentication strong
- SPF
-
v=spf1 include:amazonses.com include:_spf.google.com include:39790302.spf01.hubspotemail.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.emailpolicy: none (monitoring only) - DKIM
-
- mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - mail:
Certificate (current)
Amazon RSA 2048 M04
Expires in 88 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline';media-src * data: blob: 'unsafe-inline';- strict-transport-security
max-age=31536000; includeSubDomains
Links to (6)
- facebook.com×2
- google.com×2
- linkedin.com×2
- twitter.com×2
- youtube.com×2
- apple.com×2