openqr.io
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Cloudflare Insights
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- static.cloudflareinsights.com×1
Social
DNS records live
- NS
-
- amit.ns.cloudflare.com
- naomi.ns.cloudflare.com
- MX
-
- 1 smtp.google.com
- TXT
-
Show 4 TXT records
google-site-verification=w5lyqv4abDMJ_S2PYYT0np28Ry85KC4xSWc__cTnp4Asendinblue-code:a632c693e04004bd6c58ca72d7545ae8stripe-verification=2b028c224df9106939aedcc25825b2dff8d8e9fdd08a0416d2cec6407f97dcb7google-site-verification=LxYMkCQLaxNUOu6iQ11A8n73k5a647FPi8K9NY0HDvE
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:080ff8fd5fd24eedac134bc007bea637@dmarc-reports.cloudflare.net,mailto:info@openqr.iopolicy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkaJHBRzjmpaLQPfyCg3mBkCpO8Ps2a+zs37Q4ZfTOkZS7nuv7h3z1Kp+ZKjR3N/NeBpKCexHs6LGk8… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - dkim:
v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAssPXIckxeP0YKoaa2YxLUAmIK2toPVr5AXxJVbdSXX0KTHjM8qreOh+grABiTKLy13eZ+XHWAFIT/JHA1JoUH… - s1:
v=DKIM1;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDTDqiQ6x3q+6Gp3OE9WUYmRTzK5jqDunBmEvjzdDE5oN9r1mPv14ej0Bsf5cvcvfDamYrU1YDZJEJE2fzuK92bAR…
selectors probed - google:
Certificate (current)
E8
Expires in 26 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin, origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://fonts.googleapis.com https://*.clarity.ms/ https://static.cloudflareinsights.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https: http:; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com https://cloudflareinsights.com https://*.clarity.ms- strict-transport-security
max-age=2592000; preload- cross-origin-opener-policy
same-origin-allow-popups