sovos.com
HTML metadata
Technology
- Server
- Pagely-ARES
- CMS
- WordPress
Third-party hosts loaded (3)
- fast.wistia.net×1
- js.chargebee.com×1
- script.crazyegg.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2008-04-19
- Expires
- 2027-04-19 334 days left
- Updated
- 2026-03-23
- Name servers
-
- ns0.dnsmadeeasy.com
- ns1.dnsmadeeasy.com
- ns2.dnsmadeeasy.com
- ns3.dnsmadeeasy.com
DNS records live
- NS
-
- ns0.dnsmadeeasy.com
- ns1.dnsmadeeasy.com
- ns2.dnsmadeeasy.com
- ns3.dnsmadeeasy.com
- MX
-
- 0 sovos-com.mail.protection.outlook.com
- TXT
-
Show 19 TXT records
atlassian-domain-verification=LoyLucaw/2T7g5hbeDvNSveY6z7s6Ls4/frEpFjclDiS1/4XpQI9f7TV2YEAOb7Cps-cd-verification=a365e153-b085-4050-877f-fe8b365d8e74google-site-verification=oeZjnmAzpQG-RUMdzPC-AnPACZdqho8TXPK3VpIieBAv=verifydomain MS=3245628anthropic-domain-verification-qc03zf=3WHwrnWhgIcDUKoBzFoTKlSbzcursor-domain-verification-4npdb8=tEbTMvw0g9UobF9QHavHAcufhpostman-domain-verification=a0ebae07e70fbe13a7e5c2d71484a23e716771a7dafa034cc728d01c0b47ffd55b95eadb1540933b4f98666ad5119805429053d4d34d04e4ab00aa9400a15602LCozFI5YIeY8zj3+K5bXrLucM4pyaU27cHPt1dhmXajrshwr3X86OJ5qEGD6PMq7ijlDDi14tLd249cgpAKhRg==x121MJwxMaCoeXGjrFgNfaHGWjb3jOKkciscocidomainverification=f25319b9b40b0d2bd7b21fdf40b606ccc069a972da027548b63e08b9be934afdocker-verification=460c757d-ac1d-4c68-a9cd-fcac80dd74233862ab9e58efc8abf6e1bced2392c09d0f3f2fe40bc1ddb103sophos-domain-verification=83c617b5a6e868d0764fd0512bc5695c01dee371edefd7a386b8100146d5c4afv=spf1 a ip4:209.236.101.142 ip4:18.195.31.110 ip4:209.236.101.141 ip4:208.118.228.204 ip4:208.118.228.207 ip4:149.72.177.77 ip4:146.247.184.31 ip4:80.239.148.158 include:sendgrid.net include:mktomail.com include:mail.thoughtindustries.com include:amazonses.com include:spf.protection.outlook.com include:_spf.salesforce.com a:smtpout.cm-hosting.com -allamazonses:fYp0GheerhzLvIbj4FTjKamsPMLhgrrHpKk9cPd0wgA=brevo-code:395065fa28ece6685b98385df14f7f9bamazonses:Drf4q0Ay+LYzeoEc2KC9g/pqZy0ovLis4MqW3BFPqYI=_kvj0929tbkkt6xd7bekrb0vizclaw2agoogle-site-verification=lRMZ8zQZ7X0opxsmyQkMIuX_uE6CKcPoVduL0p9bifg
Certificate (current)
R13
Expires in 14 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(self), encrypted-media=(), fullscreen=*, geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), gamepad=(), serial=()- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; base-uri 'none'; default-src 'self' https://*.crazyegg.com; connect-src 'self' https: ws: https://*.crazyegg.com; img-src 'self' https: data: blob: https://*.sovos.com https://cdn.bfldr.com https://*.crazyegg.com; media-src 'self' data: blob: https://*.sovos.com; object-src 'self' https://*.sovos.com https://cdn.bfldr.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: data:; style-src 'self' 'unsafe-inline' https:; font-src 'self' data: https:; worker-src 'self' blob:; frame-src 'self' https://*.sovos.com https://*.youtube.com https://*.marketo.com https://fast.wistia.com https://fast.wistia.net https://js.driftt.com https://www.google.com https://www.googletagmanager.com https://documentcloud.adobe.com https://*.flowpaper.com https://e.infogram.com https://td.doubleclick.net https://recruit.hirebridge.com https://maps.google.com https://app.getreprise.com https://cdn.bfldr.com https://*.crazyegg.com; frame-ancestors 'self' https://*.sovos.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none; report-to='default'- cross-origin-resource-policy
cross-origin