paidy.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- CMS
- Gatsby
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Google Ads (DoubleClick)
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- www.google-analytics.com×2
- www.googletagmanager.com×2
- bid.g.doubleclick.net×1
- fonts.googleapis.com×1
- images.ctfassets.net×1
- ma1.ma-marunage.com×1
- s.yimg.jp×1
Social
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 2010-10-25
- Expires
- 2026-10-25 158 days left
- Updated
- 2025-09-23
- Name servers
-
- ns-1429.awsdns-50.org
- ns-1949.awsdns-51.co.uk
- ns-249.awsdns-31.com
- ns-824.awsdns-39.net
DNS records live
- NS
-
- ns-1429.awsdns-50.org
- ns-1949.awsdns-51.co.uk
- ns-249.awsdns-31.com
- ns-824.awsdns-39.net
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 14 TXT records
status-page-domain-verification=ngcmhfpbjjldMS=ms33685539_n6tse522dmu3u4yc2ibj3m7qifm5fyeadobe-idp-site-verification=55adc718261b763d233c38fefe3aa5d2ae2c46417ced9a7943777ccbb78a9c57apple-domain-verification=IN3Fm1xvbCOdrDHhatlassian-domain-verification=Q8BdHlO6NYSN5njfC2rlbPQxksVfADlcxarxq4fesYJErtGKylvfcfyfwrPD/wnvdocker-verification=750d076f-eac5-4b12-8e0e-cda023a167b6google-site-verification=DQi4KV23fzkd48stqBGUaQwFG94OHUcvByI6rfKPLxYgoogle-site-verification=Zdtf-anWE9WJIM9H_VNJHvBhuxlTR3JK799m893eX8wgoogle-site-verification=u_j8YJVEwXyApwgnTspsiB0ohFK6P_ZXyRvKtSPd2qogoogle-site-verification=vf_-xav6WqjXXmqQjQ__GMrWzlj4H9AsBfYheqjy6FQh1-domain-verification=L9EijXSLkUjk9zM23ascKzLFHW99qGniWarFX3UGi5AJoeFCmixpanel-domain-verify=be955b86-4adb-46e9-9d51-e4d6f4f778abslack-domain-verification=3NqHLbbT5fsG62WA6YFpH90VMfTptFxclA0nbIN8
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:stspg-customer.com include:sendgrid.net include:mail.zendesk.com include:7854719.spf05.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc@paidy.com,mailto:e6e0a6f299@rua.easydmarc.us; pct=100policy: quarantine - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzZC5TQQQuJgFOhFBmX9GtCM0CnEkbCZk7zerF7NocCRyexxNwg+FrvGn9yTwYl8/I+mFeEyZnU5NDE… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyIf8BXA4iUG2+QniCc2J8MD9JuhX/nlPiOTbQpElFPX26YXlNKBDNoMepsIRlMO9TCxXiHOQcpDI47y9Ja… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMSFemEnhlqg/TgZiIUWKjxaUB7EZXP9wSkW3uvXSxsDPu7GICEnV/JV8EZTWCGLX458xz4qW1gerKps0mnj1o2m… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 145 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; base-uri 'self'; default-src 'self' https://*.appsflyer.com https://*.gstatic.com https://*.paidy.com https://*.im-apps.net https://*.googletagmanager.com https://*.doubleclick.net https://*.hubspot.com https://*.youtube.com https://*.spline.design https://*.freshchat.com https://*.immedio.io https://*.clarity.ms https://*.google-analytics.com https://*.lambda-url.ap-northeast-1.on.aws https://*.analytics.google.com https://*.google.com https://*.ctfassets.net https://*.accesstrade.net; img-src 'self' data: https://*.twitter.com https://*.immedio.io https://*.impact-ad.jp https://*.clarity.ms https://*.ctfassets.net https://*.onelink.me https://t.co https://*.hubspot.com https://*.google-analytics.com https://*.google.co.jp https://*.google.com https://*.doubleclick.net https://*.bing.com https://*.yahoo.co.jp https://*.gstatic.com https://*.im-apps.net https://*.googleapis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.ma-marunage.com https:/- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (4)
- apple.com×2
- linkedin.com×2
- onelink.me×2
- twitter.com×2