pinalove.com
HTML metadata
Technology
- Server
- PWS
Third-party hosts loaded (1)
- accounts.google.com×1
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2010-12-01
- Expires
- 2028-12-01 926 days left
- Updated
- 2024-09-06
- Name servers
-
- ns-1360.awsdns-42.org
- ns-14.awsdns-01.com
- ns-2028.awsdns-61.co.uk
- ns-699.awsdns-23.net
DNS records live
- NS
-
- ns-1360.awsdns-42.org
- ns-14.awsdns-01.com
- ns-2028.awsdns-61.co.uk
- ns-699.awsdns-23.net
- MX
-
- 10 mxa.mailgun.org
- 10 mxb.mailgun.org
Email authentication strong
- SPF
-
v=spf1 include:mailgun.org include:amazonses.com ~all google-site-verification=gTAEVaCokm3VGHsnRUCq3yyNTr0W7SYSzW0FcYOIfyE google-site-verification=dGcB4aKQWpJjbrT7RcT3VGmxzzJyv8wjwirRgVgvxYIsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:help@pinalove.compolicy: reject (enforced) - DKIM
-
- default:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7/GFkpI56airA6caOapzEWP/h9xEhp69xrmNds8zf3QQ7JqgxChbHtxy9uAXDZSztjelQyNMHojrRmpdeiVi9Tge7D…
selectors probed - default:
Certificate (current)
R13
Expires in 37 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
child-src 'self';connect-src 'self' https://cognito-identity.us-west-2.amazonaws.com https://*.rekognition.amazonaws.com https://cdn.liveness.rekognition.amazonaws.com https://api.openai.com http://*.pinalove.com https://*.googletagmanager.com http://*.pinalove.com https://*.apple.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://*.pinalove.com https://*.tenor.com https://*.klipy.com https://*.pinalove.com wss: wss://*.pinalove.com wss://*.pinalove.com wss://*.vietnameselove.com;default-src 'self';font-src 'self' chrome-extension: data: http://*.gstatic.com https://*.gstatic.com;frame-src 'self' https://*.apple.com https://*.g.doubleclick.net https://*.google.com;img-src 'self' blob: data: http://*.gstatic.com https://*.googletagmanager.com http://*.pinalove.com http://*.pinalove.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.at https://*.google.be https://*.google.ca https://*.google.ch- strict-transport-security
max-age=31536000; includeSubDomains; preload