sporteasy.net
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- static.zdassets.com×2
- www.googletagmanager.com×2
- sdk.privacy-center.org×1
- www.youtube.com×1
Social
Registration
- Registrar
- Gandi SAS
- Created
- 2010-05-24
- Expires
- 2029-05-24 1101 days left
- Updated
- 2026-01-16
- Name servers
-
- ns-118-c.gandi.net
- ns-226-b.gandi.net
- ns-24-a.gandi.net
DNS records live
- NS
-
- ns-118-c.gandi.net
- ns-226-b.gandi.net
- ns-24-a.gandi.net
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
Show 4 TXT records
sendinblue-code:734185bd03e2d3f64042cbea06fb9b46facebook-domain-verification=x0mh4p0su3sx3lykc92ukkxlr16nkjdust-domain-verification-67w7ve=ohQtDKW833zOjcMw0zeAnVNKA30nq68bxqp1ydh04zzmjqbcrxll97p4l
Email authentication strong
- SPF
-
v=spf1 include:spf.sendinblue.com mx include:_spf.google.com include:mail.zendesk.com include:9489272.spf02.hubspotemail.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:dmarc@sporteasy.net!10m,mailto:re+d7cdd1985723@inbound.dmarcdigests.com; ruf=mailto:dmarc@sporteasy.net!10m; rf=afrf; pct=100; ri=86400policy: quarantine · sp=quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsZAjcDoQRtQC2SwGNvB4Voiif/tBXChvDng++b+QvywYirkKilnGmyTkjucfrdgecKWWVLkZKEr/qc… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - google:
Certificate (current)
R12
Expires in 29 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
same-origin- permissions-policy
accelerometer=(),autoplay=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.doubleclick.net *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.youtube.com *.ytimg.com *.zdassets.com assets.tumblr.com connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsadspixel.net js.hscollectedforms.net js.hscollectedforms.net js.hsforms.net js.hsleadflows.net js.hsleadflows.net js.hubspot.com js.hubspot.com js.usemessages.com script.hotjar.com sdk.privacy-center.org sibforms.com snap.licdn.com static.hotjar.com data:; style-src 'unsafe-inline' * blob: data:; img-src * blob: data:; font-src 'unsafe-inline' * data:; frame-src 'self' blob: *.doubleclick.net *.google.com *.googletagmanager.com *.typeform.com *.youtube-nocookie.com *.youtube-nocookie.com *.youtube.com app.hubspot.com forms.hsforms.com; child-src 'self' blob: *.doubleclick.net *.googletagmanager.com *.youtube-nocookie.c- strict-transport-security
max-age=86400