quotient-inc.com
HTML metadata
Technology
- Server
- Apache
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (4)
- fonts.googleapis.com×3
- player.vimeo.com×1
- s7.addthis.com×1
- www.googletagmanager.com×1
Social
Contact
Registration
- Registrar
- Porkbun LLC
- Created
- 1999-01-27
- Expires
- 2027-01-27 235 days left
- Updated
- 2026-01-05
- Name servers
-
- curitiba.ns.porkbun.com
- fortaleza.ns.porkbun.com
- maceio.ns.porkbun.com
- salvador.ns.porkbun.com
DNS records live
- NS
-
- curitiba.ns.porkbun.com
- fortaleza.ns.porkbun.com
- maceio.ns.porkbun.com
- salvador.ns.porkbun.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
atlassian-sending-domain-verification=c3e13422-7c19-4766-89ce-9aa0fadc3158
- Verified for
-
- Atlassian
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:96.234.207.34 ip4:96.234.207.38 ip4:52.33.64.11 ip4:52.13.39.81 ip4:167.89.11.197 ip4:46.23.89.24 include:_spf.google.com include:_spf.atlassian.net include:_spf.psm.knowbe4.com include:u5643561.wl062.sendgrid.net include:u58604856.wl107.sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:dmarc@quotient-inc.com;ruf=mailto:dmarc@quotient-inc.com;aspf=s;adkim=r;fo=1policy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhCLruzdr8Nal1mJlF5wSmzG01uYKd7I9N7pxKw0TgsVv6qkO9dHgkgK0Fa9yQdc/sWECACBngblboV… - selector1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtjOuYgHm3b6hI90WX5J6ynP31ukAlTTAGKTeYgB3MGT/81NtPZub1EZfN4SWIEP3yp4YEmIRlq19l7+lyw… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvn85EdMzZyDCk+XyUAyDcgwjdGM4ZY31Gi1D8i2HGGzuWac/9bsHyBcY5fjT/zR8Lbb9GSdQYl11NxSBD9… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwV7lRljlNzEGRKB72XIj8HaZ/0XlZ5vnIFXobMICQ1O33E9a/lPjorZTkDfhMUkZbawZt8mUxuZ9GEyNFz…
selectors probed - google:
Certificate (current)
E8
Expires in 28 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(self), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src * 'unsafe-inline' 'unsafe-eval' data: blob:;- strict-transport-security
max-age=63072000; includeSubDomains; preload