paper-leaf.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (15)
- www.google.com×3
- www.googletagmanager.com×2
- ajax.googleapis.com×1
- cdn-cookieyes.com×1
- cdn.jsdelivr.net×1
- cdnjs.cloudflare.com×1
- gmpg.org×1
- js-na1.hs-scripts.com×1
- js.hs-analytics.net×1
- js.hs-banner.com×1
- js.hsadspixel.net×1
- sc.lfeeder.com×1
- script.crazyegg.com×1
- snap.licdn.com×1
- www.gstatic.com×1
Social
Contact
- Phone
- Address
- 10217 106 St #200, T5J1H5, Edmonton, AB, CA
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 2009-07-30
- Expires
- 2026-07-30 70 days left
- Updated
- 2025-07-25
- Name servers
-
- ns1.digitalocean.com
- ns2.digitalocean.com
- ns3.digitalocean.com
DNS records live
- NS
-
- ns1.digitalocean.com
- ns2.digitalocean.com
- ns3.digitalocean.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
knowbe4-site-verification=6c6b52e7a32ea2d79572e4d1bed8e8f6TAILSCALE-D4RR451iSaoCKEWh6XxXamazon-business-verification=9af3a030afb3ca139896d22d5c73d1879d88fd548124c87e4f497d474f804820
- Verified for
-
- 1Password
- Apple
- Atlassian
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a mx include:_spf.google.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:tech+pl.dmarc@zgm.ca; ruf=mailto:tech+pl.dmarc@zgm.ca; sp=none;policy: none (monitoring only) · sp=none - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAm7IVusJVNOUNaKqVd6MvcVWCQHyJVzWtDKBVVhU5ECmIoEDhvvZHOapSaivE/oTi8hnykTNIpafEAN… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyvze51JYKoMV1wRzy9wtnVEfmHNNReQgWP3mcvQ4lhPqSEruY1k+xKl0mU7q1E7l5rOO0w3oIoX1QC…
selectors probed - google:
Certificate (current)
R13
Expired 11 days ago
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin, strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(self), camera=(), encrypted-media=(self), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: data: 'unsafe-inline' https://*.crazyegg.com https://*.doubleclick.net https://*.facebook.com https://*.facebook.net https://*.google.ca https://*.google.com https://*.gstatic.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hs-scripts.com https://*.hsadspixel.net https://*.hubapi.com https://*.hubspot.com https://*.lfeeder.com https://*.typekit.net https://ajax.googleapis.com https://cdn-cookieyes.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://log.cookieyes.com/api/v1/log https://pagead2.googlesyndication.com https://px.ads.linkedin.com https://secure.gravatar.com https://snap.licdn.com https://static.hsappstatic.net https://www.google-analytics.com https://www.googletagmanager.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none; report-to='default'- cross-origin-resource-policy
cross-origin