spherical.co
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- js.hs-scripts.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- 200 Centre St, 3rd Floor, 10013, New York, NY, US
DNS records live
- NS
-
- ns-1215.awsdns-23.org
- ns-1804.awsdns-33.co.uk
- ns-248.awsdns-31.com
- ns-926.awsdns-51.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
- Apple
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:postmaster@spherical.copolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 263 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin, same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src-elem 'self' 'unsafe-inline' js-na1.hs-scripts.com *.facebook.net *.doubleclick.net js.hs-scripts.com *.googletagmanager.com js.hs-analytics.net js.hs-banner.com js.hsadspixel.net *.google.com *.gstatic.com js.hubspot.com js.hsforms.net static.hsappstatic.net; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com; style-src-attr 'unsafe-inline'; img-src 'self' data: *.google.co.jp *.google.ch *.google.nl *.google.hu *.google.fr *.google.de *.google.com.hk *.google.com.bd *.google.co.kr stats.g.doubleclick.net *.google.com.ag *.google.fr *.googleadservices.com *.gravatar.com *.hubspot.com *.bugherd.com *.facebook.com *.google.al *.google.com *.google.es *.googletagmanager.com *.google.co.uk *.google.co.za *.google.com.pr *.w.org s3.dualstack.us-east-1.amazonaws.com *.google.ca *.google.co.in *.google.co.nz *.google.com.eg *.google.com.ph *.google.com.pk *.google.co.id static.hsappstatic.net forms-na1.hsforms.com; font-src 'self' data: *.gstatic.com; connect-src 's- strict-transport-security
max-age=63072000; includeSubDomains; preload