studyteamapp.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (4)
- assets.calendly.com×2
- unpkg.com×2
- cdn.jsdelivr.net×1
- consent.cookiebot.com×1
Contact
- Phone
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2017-04-01
- Expires
- 2027-04-01 316 days left
- Updated
- 2026-02-25
- Name servers
-
- ns-1529.awsdns-63.org
- ns-1785.awsdns-31.co.uk
- ns-188.awsdns-23.com
- ns-655.awsdns-17.net
DNS records live
- NS
-
- ns-1529.awsdns-63.org
- ns-1785.awsdns-31.co.uk
- ns-188.awsdns-23.com
- ns-655.awsdns-17.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
v=spf1 include:spf.mandrillapp.com include:_spf.google.com include:amazonses.com ~all
Certificate (current)
Amazon RSA 2048 M03
Expires in 124 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
report-uri report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubdb6d1eb0f615efd9131c3c147eb3994c&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aproduction%2Cservice%3Acloudfront;; default-src 'self' *.studyteamapp.cn *.studyteamapp.com *.reifyapp.com *.onestudyteam.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.studyteamapp.cn *.studyteamapp.com *.onestudyteam.com js.hsforms.net *.google.com *.gstatic.com *.cloudflare.com *.wistia.com *.wistia.net *.cookiebot.com *.zendesk.com *.zdassets.com *.calendly.com *.pendo.io *.localizecdn.com fonts.googleapis.com maps.googleapis.com unpkg.com cdn.jsdelivr.net *.storage.googleapis.com; style-src 'self' 'unsafe-inline' *.studyteamapp.cn *.studyteamapp.com *.onestudyteam.com *.typekit.net *.calendly.com unpkg.com fonts.googleapis.com *.wistia.com *.storage.googleapis.com; img-src 'self' *.studyteamapp.cn *.studyteamapp.com *.onestudyteam.com blob: data: *.hsforms.com *.wistia.net *.w- strict-transport-security
max-age=31536000; includeSubDomains