sitesee.co
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- d3alngem7je9z2.cloudfront.net×6
- www.googletagmanager.com×2
Social
DNS records live
- NS
-
- ns1.digitalocean.com
- ns2.digitalocean.com
- ns3.digitalocean.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=9gDPIIw_O4Yt0Y_ZbV2lIzMXC2eLwQgXVDOLJ5R7WMA
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 70 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' js.stripe.com www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: djt888zcr9vad.cloudfront.net d3alngem7je9z2.cloudfront.net d1lpgp6dpxwvie.cloudfront.net d1dwpr2yi6waz7.cloudfront.net; font-src 'self' d3alngem7je9z2.cloudfront.net; connect-src 'self' https://lhtxzbgoibsgxyausavf.supabase.co wss://lhtxzbgoibsgxyausavf.supabase.co https://api.stripe.com https://*.sentry.io https://www.google-analytics.com https://region1.google-analytics.com https://djt888zcr9vad.cloudfront.net; frame-src js.stripe.com hooks.stripe.com; worker-src blob:; object-src 'none'; base-uri 'self'- strict-transport-security
max-age=31536000; includeSubDomains
Links to (26)
- do.co×2
- twitter.com×2
- google.com×2
- typewolf.com×1
- 23gradicoffee.com×1
- accurat.it×1
- bsky.app×1
- careofchan.com×1
- facebook.com×1
- instagram.com×1
- jimmyfairly.com×1
- lukejones.me×1
- mason-fifth.com×1
- thenounproject.com×1
- threads.com×1
- drafta.co×1
- five-four.co×1
- densediscovery.com×1
- grsm.io×1
- hourly-app.com×1
- mailchimp.com×1
- missionmedia.com×1
- overflow.io×1
- petalcard.com×1
- berlinbyfood.eu×1
- apple.com×1