rentahuman.ai
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (6)
- use.typekit.net×3
- firebaseinstallations.googleapis.com×1
- firebasestorage.googleapis.com×1
- identitytoolkit.googleapis.com×1
- js.stripe.com×1
- us.i.posthog.com×1
Registration
- Registrar
- Cloudflare, Inc
- Created
- 2026-02-01
- Expires
- 2031-02-01 1716 days left
- Updated
- 2026-02-22
- Name servers
-
- nia.ns.cloudflare.com
- major.ns.cloudflare.com
DNS records live
- NS
-
- major.ns.cloudflare.com
- nia.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com include:send.resend.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:alex@rentahuman.aipolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArl/Kxf6cyEcI4BqHLdQGLeK8J5Aokwvvkz27/RLWDz9rZyE3euCgweUiff3FvokSrj2QfLAic5TZxsoq…
selectors probed - google:
Certificate (current)
WE1
Expires in 40 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'nonce-eaWSCIJGZKhmO6HKfAIHhA==' https://js.stripe.com https://apis.google.com https://*.firebaseapp.com https://static.cloudflareinsights.com https://www.google.com https://www.gstatic.com https://challenges.cloudflare.com https://*.posthog.com 'strict-dynamic'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net; font-src 'self' https://fonts.gstatic.com https://use.typekit.net; img-src 'self' data: https: blob:; media-src 'self' https: blob:; connect-src 'self' https://*.googleapis.com https://*.firebaseio.com wss://*.firebaseio.com https://firebasestorage.googleapis.com https://identitytoolkit.googleapis.com https://*.firebaseapp.com https://auth.rentahuman.ai https://checkout.stripe.com https://api.stripe.com https://m.stripe.com https://www.google.com https://challenges.cloudflare.com https://*.posthog.com https://securetoken.googleapis.com https://*.cloudfunctions.net; frame-src 'self'- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-resource-policy
same-origin