ortto.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- Framer
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- framerusercontent.com×138
- events.framer.com×1
- fonts.gstatic.com×1
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2016-01-03
- Expires
- 2027-01-03 229 days left
- Updated
- 2024-06-17
- Name servers
-
- ns-1089.awsdns-08.org
- ns-1998.awsdns-57.co.uk
- ns-237.awsdns-29.com
- ns-717.awsdns-25.net
DNS records live
- NS
-
- ns-1089.awsdns-08.org
- ns-1998.awsdns-57.co.uk
- ns-237.awsdns-29.com
- ns-717.awsdns-25.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 9 TXT records
mongodb-site-verification=X7horHrIMUZISYfB5rUGgazxG2Gskawxtwilio-domain-verification=065f8469cfac91cc5a93ae1da3cffca8OSSRH-86650anthropic-domain-verification-gfrwdy=KsPpGnLyKduZKiZZkXgCbwWK0atlassian-domain-verification=4XsSBi05dL8BHGQppQ0PyQshua56URanaOW3MWfR4IO718DeWIXDIi9yEEio5Icogoogle-site-verification=4-Qkov9TcZm4DUvJbSmlzgijoSs2NS2se6CnvE9Sg3wgoogle-site-verification=Wk7g8TU-J_oLfliDl5HwAX7NgXWGdSxCwu31LlbAsjUgoogle-site-verification=vpHtmDCzx33cHoyTVeakEMvxBCEIafrBxsgR-YnkEFwknowbe4-site-verification=b942c42114987e8f3b2dfa74dff2b3f1
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:_spf.salesforce.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc@orttohq.uriports.com; ruf=mailto:dmarc@orttohq.uriports.com; fo=1:d:spolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAk7Kn+VdpoWQ3/mLq1v4uZPlH7D/f4+XMWszQasusegz0Ehd83bCpP9wGmxbOcyARbpU6clQ0CyxOIb…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 221 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=*, fullscreen=*, microphone=*- x-content-type-options
nosniff- content-security-policy
connect-src 'self' https: wss:; default-src 'self' https:; frame-ancestors 'self'; img-src 'self' https: data:; media-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' blob:; script-src https: 'unsafe-inline'; style-src 'self' https: 'unsafe-inline'- strict-transport-security
max-age=31536000- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin