skilllab.io
HTML metadata
Technology
- CMS
- Next.js
Social
DNS records live
- NS
-
- ns-cloud-c1.googledomains.com
- ns-cloud-c2.googledomains.com
- ns-cloud-c3.googledomains.com
- ns-cloud-c4.googledomains.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
mixpanel-domain-verify=edec1bd8-9b4a-4139-babf-68371dd4063fMS=E4F1608896B068542C5BC83AF506E22CAF0AD185
- Verified for
-
- Apple
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:spf.mandrillapp.com include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc-reports@skilllab.iopolicy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAujs3qXAdWkfZLfXvNmVqDGDga3IpRKGQfjzj1d2O3r0J+NTEfmw6F72nEyQ2ZuazoFr9WkxbVtj9Mm… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvrYWhyq1jGT8hABsJlIcytgkHMf9vno2rFZ9kiTW+LZaRcWGVd2nWVOq4Mp49IaPj9/6j89GQR+KpQhRSD… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4Epd39FYeRJsRpGx1Z2Rt5JpHQAKvzJCpXVFhpoumj5AtC1oJHXf/vg26P6rjVxBh1OvchUogopcIyFMWt…
selectors probed - google:
Certificate (current)
WR3
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' skilllab.prismic.io skilllab.cdn.prismic.io; script-src 'self' 'unsafe-inline' *.google.com *.gstatic.com *.googletagmanager.com *.hs-scripts.com *.hs-analytics.net *.hscollectedforms.net *.hs-banner.com *.hsforms.net forms.hsforms.com static.hsappstatic.net static.cdn.prismic.io; connect-src 'self' *.googleapis.com *.google-analytics.com skilllab.prismic.io forms.hubspot.com forms.hsforms.com hubspot-forms-static-embed.s3.amazonaws.com *.hscollectedforms.net skilllab.cdn.prismic.io; object-src 'none'; img-src 'self' skilllab.cdn.prismic.io images.prismic.io *.google-analytics.com *.googletagmanager.com forms.hsforms.com perf.hsforms.com forms.hubspot.com track.hubspot.com; frame-src meet.skilllab.io *.youtube.com forms.hsforms.com *.google.com; style-src 'self' 'unsafe-inline'; child-src https://www.youtube.com; media-src https://prismic-io.s3.amazonaws.com;- strict-transport-security
max-age=31556926