poppy.com

.com crawl

First seen 2026-05-14 · Last seen 2026-05-19 · ok HTTP/1.1 200 5883 ms crawled 2026-05-19

US · 185.230.63.107 · AS58182 Wix.com Ltd.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Poppy — Healthy Sustainable Buildings
Description
Poppy is Energy Optimization for Healthy Buildings, serving over 50M SF of commercial buildings in the US, Canada and the Middle East.
Language
en

Open Graph

title
Poppy — Healthy Sustainable Buildings
locale
en_US
site name
Poppy
description
Poppy is Energy Optimization for Healthy Buildings, serving over 50M SF of commercial buildings in the US, Canada and the Middle East.

Technology

Server
railway-edge
CMS
Next.js

Social

Contact

Address
941 W. Morse Blvd, Ste 100Winter Park, FL 32789

Registration

Registrar
NameCheap, Inc.
Created
1995-09-08
Expires
2027-09-07 474 days left
Updated
2025-08-11
Name servers
  • ns4.wixdns.net
  • ns5.wixdns.net

DNS records live

NS
  • ns4.wixdns.net
  • ns5.wixdns.net
MX
  • 10 aspmx.l.google.com
  • 20 alt1.aspmx.l.google.com
  • 30 alt2.aspmx.l.google.com
  • 40 alt3.aspmx.l.google.com
  • 50 alt4.aspmx.l.google.com
TXT
  • ppe-d169fcc0d30c959ee4ad56c0b4ee020437f65c72
  • ca3-9ab0b47df8654ec1bb1f5b93c99b684b
Verified for
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 ip4:107.20.210.250 ip4:52.1.14.157 ip4:107.23.16.222 ip4:54.173.83.138 include:24453899.spf02.hubspotemail.net include:_spf.google.com include:amazonses.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx++hlZz/Ddn3/6wHy1F3BR6jkCZ9gAoFFwj7YnKcNnrxQCZ7E62qNegk8sCYJZTInjUswKMU1z2LbX…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3o0MvDrInHLtIjE0nkOX4JLf0myRL7oWJPG4H6g6DGEMRvk/mr0PMEj9v/B7dGTFJwSf7xXF/WXvvPqIlb…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0lInY92LT5GGTbyVcXM6fBNhgnOgqYtlFQt98wvre3vJVqM/cfPuGe7WBhrSmOnyg2+zpeXWigO/AyaawD…
selectors probed

Certificate (current)

R12
from 2026-03-09 to 2026-06-07
Expires in 18 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://www.poppy.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
camera=(), microphone=(), geolocation=(), interest-cohort=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.hsappstatic.net; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self'; connect-src 'self' https://api.hsforms.com https://meetings.hubspot.com; frame-src 'self' https://meetings.hubspot.com; frame-ancestors 'none'
strict-transport-security
max-age=63072000; includeSubDomains; preload

Links to (2)

Linked from (1)