onto.app
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×2
Social
Contact
DNS records live
- NS
-
- ns-183-a.gandi.net
- ns-217-b.gandi.net
- ns-76-c.gandi.net
- MX
-
- 10 mx1.privateemail.com
- 10 mx2.privateemail.com
- TXT
-
ywxnbjjrjs6675lqqmd25lc0r191lglbgoogle-site-verification=tOq4i0yq-NUaWPSbGYgoJDphYIsMYakYUiASN9tfXZM223b3d94-1321-4d4a-a1cc-43a4efcf96de=646d48c32049131d415b983d31bbb82e9f85a619af24cd5fef06db3531b2f5ad
Email authentication strong
- SPF
-
v=spf1 include:spf.privateemail.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:contact@onto.apppolicy: reject (enforced) - DKIM
-
- default:
v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv7BaHujKcK8cgrSvYzkGRUVd9MEMy7AxizykBbM16n2I8vLg3WAEYUSKNWGBg4w+6NoeEfbBkPFJqztt…
selectors probed - default:
Certificate (current)
E7
Expires in 54 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- findings
-
- missing HSTS
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- content-security-policy
frame-ancestors 'self' onto.app *.onto.app
Links to (5)
- github.com×2
- medium.com×2
- ont.io×2
- t.me×2
- twitter.com×2
Linked from (1)
- ont.io×2