playtoearn.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- cdnjs.cloudflare.com×5
- fonts.googleapis.com×3
- cdn.jsdelivr.net×2
- accounts.google.com×1
- ajax.googleapis.com×1
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2008-07-23
- Expires
- 2027-07-23 430 days left
- Updated
- 2024-04-26
- Name servers
-
- bayan.ns.cloudflare.com
- grace.ns.cloudflare.com
DNS records live
- NS
-
- bayan.ns.cloudflare.com
- grace.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-gws-recovery-domain-verification=51323429google-site-verification=EdcEvlXufHVk65ft1VdbR3dI8C9ZpuQ68Q5vcXybHewgoogle-site-verification=QkPSc3w8idTOPTmZxB0Cnee5i75v11JNYWvNqQGThnw
Email authentication strong
- SPF
-
v=spf1 include:secureserver.net include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:2a8e15d26231485fab4d33a66e1bc806@dmarc-reports.cloudflare.netpolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAr7WEoXCBoyz6vD6In3zamftCaSYzwrYFoY0KauaGD8IXPPj+fbp1xi7JFJ7v4nYyZYbnkX1hyu3CpL…
selectors probed - google:
Certificate (current)
WE1
Expires in 35 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
DENY- permissions-policy
geolocation=(self)- x-content-type-options
nosniff- content-security-policy
default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src * data: blob: 'unsafe-inline'; img-src * data: blob:; frame-src *; font-src * data:; connect-src *; media-src *; object-src *; child-src *; form-action *; frame-ancestors *; base-uri *;- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (12)
- discord.com×2
- facebook.com×2
- google.com×2
- instagram.com×2
- linkedin.com×2
- metamask.io×2
- phantom.app×2
- spotify.com×2
- t.me×2
- tiktok.com×2
- twitter.com×2
- youtube.com×2