recman.io
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
Social
DNS records live
- NS
-
- ns-1438.awsdns-51.org
- ns-1973.awsdns-54.co.uk
- ns-386.awsdns-48.com
- ns-702.awsdns-23.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
knowbe4-site-verification=f49b4f8387d31de34610189cb6eb9fd3
- Verified for
-
- Anthropic
- Postman
- Slack
Email authentication partial
- SPF
-
v=spf1 include:servers.mcsv.net include:_spf.google.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApjsPVPOkNluZYFWPmnbvf/SLzIzX+2MQkpRBnxUbhUnf5nLuuDNRLiAwI0pR+I09GjvFcTuTOOpT66… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M03
Expires in 95 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self' ; img-src 'self' data: blob: *.recman.no *.recman.io *.capterra.com *.google-analytics.com *.bing.com *.clarity.ms *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.linkedin.com www.facebook.com *.google.com *.google.no *.google.se *.google.co.uk *.google.dk *.google.nl *.google.fi *.google.ua *.google.com.au *.google.com.ua *.google.com.co *.google.es *.google.pl *.google.ro; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.jsdelivr.net *.mouseflow.com *.youtube.com *.googletagmanager.com *.clarity.ms connect.facebook.net www.googleadservices.com googleads.g.doubleclick.net www.google.com snap.licdn.com; style-src 'self' 'unsafe-inline'; media-src 'self'; font-src 'self' data:; frame-src 'self' *.doubleclick.net *.youtube.com player.vimeo.com www.googletagmanager.com; frame-ancestors 'none'; object-src 'none'; connect-src 'self' *.facebook.com *.clarity.ms *.l- strict-transport-security
max-age=31536000; includeSubDomains; preload