orkes.io
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (12)
- cdn.prod.website-files.com×254
- px.ads.linkedin.com×3
- www.googletagmanager.com×3
- ajax.googleapis.com×1
- buttons.github.io×1
- cdn.lgrckt-in.com×1
- d3e54v103j8qbb.cloudfront.net×1
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- hubspotonwebflow.com×1
- js.hsforms.net×1
- unpkg.com×1
Social
DNS records live
- NS
-
- ns-1308.awsdns-35.org
- ns-132.awsdns-16.com
- ns-1615.awsdns-09.co.uk
- ns-730.awsdns-27.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
stripe-verification=43a7aa0e24f26d234a18b63d37a089ced6a51febde4fab5b5161fad847471361MS=ms63200696asv=5f8f7f1145d1b93f21b1d2653adc35fbatlassian-domain-verification=7JbUmf7eJjdBiEKJ0C2kNNRlOPNia9/NCeXauZc8cTKi/qL2g/9Q6NHF9vQIgom1clojars <orkes_io>google-site-verification=uFtzBkB9CQYpgZK_vTx7ApZZ7ISLk30JR00R2ArbZfg
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com include:hubspotemail.net include:20882608.spf01.hubspotemail.net include:sendgrid.net a:dispatch-us.ppe-hosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; sp=none; adkim=r; aspf=r; fo=1; pct=100; rua=mailto:re+12f5f224a3b8@inbound.dmarcdigests.compolicy: quarantine · sp=none - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9G5GosiFFbuKJHMxUna/zzs34IDuonwuJkmevhOlkEzEyxM08/2m0xcy/vBoiO9CRpVncYih06vOf/… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzRDpHMfLB3z80QekAgZzxFFz3bMVF/oOZCzU2ZP+kSgcUn+eZo7e7ltokSmBCYmV/CF5AwfiHbLKCafkND… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0KCaPlWTTO0MKRNpqbaGuTOyORyCP7QnAZ/0rHSLy4IoqoTtLPhKALXD+WlFv6lzlwlg9aiTddoWzDYTsC…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 151 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- findings
-
- missing HSTS
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
frame-ancestors 'self' https://*.webflow.com http://*.webflow.com http://*.webflow.io http://webflow.com https://webflow.com