proton.me
HTML metadata
Technology
- CMS
- Gatsby
Third-party hosts loaded (1)
- pmecdn.protonweb.com×99
Social
Contact
- Address
- Route de la Galaise 32, 1228, Plan-les-Ouates, Geneva, Switzerland
DNS records live
- NS
-
- ns1.proton.me
- ns2.proton.me
- ns3.proton.me
- MX
-
- 10 mail.protonmail.ch
- 20 mailsec.protonmail.ch
- TXT
-
Show 9 TXT records
google-site-verification=MUjtKY-4uQAjE92Z2-s1nm9m4mvdqY2z6HCvi_Bj4sogoogle-site-verification=_ayl1WqWIag2WkIbK4sNg_x3NCT5nYOl_DgtFPTYKeggoogle-site-verification=4UIZgETX8lGnv0WwpeJJbszo9daKOdXXYBKCA2XLf94zoom-domain-verification=ZOOM_verify_5990c1fbb09d4c6aba062cded6cbdf06protonmail-verification=5262a92f988e64f1be1362138befdf1e19d6a4c1google-site-verification=QviHfE1VQ57-tDmDLxM6BQH1mdgvdQ_0QsIvCht2IaUyandex-verification: 95a7888a0f987e6alinkedin-site-verification=01e79150-bf68-4e0c-ad04-822dc1015b3bgoogle-site-verification=2FGIDo-Gf-lWE6t_gWd9gpPTehHD85hbNiEujPVgysc
Email authentication strong
- SPF
-
v=spf1 include:_spf.protonmail.ch ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; aspf=s; adkim=s;policy: quarantine - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 86 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self'; media-src https://static.zdassets.com https://res.cloudinary.com https://pmecdn.protonweb.com; connect-src 'self' wss: https://protonmail.zendesk.com https://ekr.zdassets.com blob: https://account.proton.me https://reports.proton.me https://telemetry.proton.me https://*.algolia.net https://*.algolianet.com https://go.getproton.me https://noembed.com https://boards-api.greenhouse.io https://proton.me https://*.paypal.com https://*.paypalobjects.com; script-src 'self' blob: 'unsafe-eval' 'unsafe-inline' https://static.zdassets.com https://pmecdn.protonweb.com https://www.youtube.com https://platform.twitter.com https://*.paypal.com https://*.paypalobjects.com; style-src 'self' 'unsafe-inline' https://pmecdn.protonweb.com https://*.paypal.com https://*.paypalobjects.com; font-src 'self' https://pmecdn.protonweb.com; img-src 'self' data: blob: https:; frame-src 'self' data: blob: https://www.youtube-nocookie.com https://platform.twitter.com https://*.paypal.com https:/- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (14)
- bsky.app×4
- facebook.com×4
- instagram.com×4
- linkedin.com×4
- protonvpn.com×4
- reddit.com×4
- simplelogin.io×4
- standardnotes.com×4
- t.me×4
- threads.net×4
- tiktok.com×4
- uservoice.com×4
- x.com×4
- youtube.com×4
Linked from (50)
- protonmail.com×11
- protonvpn.com×8
- jaaklac.org×4
- whistleblower-net.de×4
- gdpr.eu×4
- freestuff.dev×3
- noyb.eu×3
- feettothefireradio.com×3
- stephanelambion.com×3
- 9to5google.com×3
- standardnotes.com×3
- simplelogin.io×3
- keepandroidopen.org×2
- fol74.org×2
- eutechalliance.eu×2
- michalis.xyz×2
- safewhistle.info×2
- papaditu.com×2
- zhainandaohang.com×2
- huang360.com×2
- 18hdh.com×2
- xingkongrukou.com×2
- crfldh.com×2
- fuliditu.com×2
- xingba360.com×2
- seqing360.com×2
- madou360.com×2
- haosebao.com×2
- seseditu.com×2
- sex2048.com×2
- 18avdh.com×2
- fulimap.com×2
- wuyedh.com×2
- langyoudaohang.com×2
- diwanghuisuo.com×2
- 51sejie.com×2
- yanjiusuo520.com×2
- crsqdh.com×2
- baozangrukou.com×2
- 9sdh.com×2
- zzdh520.com×2
- fuli360.com×2
- mimi2048.com×2
- xxoo1024.com×2
- shenmirukou.com×2
- buliang520.com×2
- 18qingse.com×2
- yequ360.com×2
- wuyedaohang.com×2
- mitaodaohang.com×2