orderlyemails.com

.com crawl

First seen 2026-05-08 · Last seen 2026-05-08 · ok HTTP/1.1 200 4590 ms crawled 2026-05-15

US · 172.67.74.147 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

sector tech type app saas

HTML metadata

Title
Shopify App — Installation
Language
en

Technology

CDN
Cloudflare

Registration

Registrar
1API GmbH
Created
2016-02-12
Expires
2027-02-12 268 days left
Updated
2026-02-07
Name servers
  • cortney.ns.cloudflare.com
  • seamus.ns.cloudflare.com

DNS records live

NS
  • cortney.ns.cloudflare.com
  • seamus.ns.cloudflare.com
MX
  • 10 mxa.mailgun.org
  • 10 mxb.mailgun.org
Verified for
  • Google
  • Meta

Email authentication partial

SPF
v=spf1 include:sendgrid.net include:spf.mail.intercom.io include:forsbergplustwo.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none
policy: none (monitoring only)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5rMUWM/l4ePW+V2B21jYTtkYm+ZiPiKzrZiVK9xXJn1ju+eixez9k+58BsDZuejyKW8YgbpUtrdik4i3oL…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCjtTdsWFkwTonm42VowczEJIFWD+rW+C6d6MzqPmmfQJzFVVX5+rdHljdt9kVX4dfZdX2saeVImLZUkppWLpG42l…
selectors probed

Certificate (current)

WE1
from 2026-03-29 to 2026-06-27
Expires in 38 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.orderlyemails.com/login

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-content-type-options
nosniff
content-security-policy
frame-ancestors 'self' https://admin.shopify.com https://*.myshopify.com https://oe.local https://*.oe.local https://cdn.oe.local https://cdn.orderlyemails.com https://app.chatwoot.com; font-src 'self' https: data: https://cdn.oe.local https://*.oe.local https://cdn.oe.local https://cdn.orderlyemails.com https://fonts.googleapis.com https://app.chatwoot.com; style-src 'self' https: 'unsafe-inline' https://cdn.oe.local https://cdn.orderlyemails.com https://fonts.googleapis.com https://kit.fontawesome.com https://www.googletagmanager.com https://cdn.shopify.com https://app.chatwoot.com; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' https://cdn.oe.local https://cdn.orderlyemails.com https://fonts.googleapis.com https://kit.fontawesome.com https://www.googletagmanager.com https://cdn.shopify.com https://app.chatwoot.com
strict-transport-security
max-age=63072000; includeSubDomains

Linked from (1)