sundayapp.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- www.googletagmanager.com×2
- gmpg.org×1
Social
Registration
- Registrar
- OVH sas
- Created
- 2017-03-13
- Expires
- 2027-03-13 297 days left
- Updated
- 2026-03-14
- Name servers
-
- dns200.anycast.me
- ns200.anycast.me
DNS records live
- NS
-
- dns200.anycast.me
- ns200.anycast.me
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 29 TXT records
MS=ms57358412ext.teamtailor.comca3-939df5b4003c4030867ce179204db17aca3-4e9be9219cb041a3b945c05fe3f33b9e996150e6537c2e63504036cd34e0800cuber-domain-verification=2c7825d9-50b4-4463-bf55-db9f26459929linear-domain-verification=dkjpbzttqeqwCKO=cli_7hkfe4fupbtehmkipgbnwckvbmstripe-verification=68B946E95D3405DF30A7D58552B8DA1DCFD5BEE5DE6BBE875AE3A221EFEAF765f30f0755550e52dd5129c091bcbad6feaf3e99f8872c5406102c529c88c95577google-site-verification=i_7-xg-74677Fid28FATSvNofXc0Ih-qXR3_H3wgrDYbrevo-code:71c2701b7083fb1b59375fb5891f72acatlassian-domain-verification=rhtJq8rEXbVi3ZidNbTewUCDoRbSda9tSRQ7qNhhv2kRpEK3zvuJKVmZMRRL6nsSgoogle-site-verification=ar1FMlHMJACvg75gv-9Tkaiwuq31F6i-B1i-pMCY_bMfacebook-domain-verification=o0tev8qcr7utuqj2jkagijs47273jdgoogle-site-verification=9V0r5ZbFmP0gqb3NEk9wKn-3a5uNWmG68MIWy-GD-LAsegment-site-verification=8XYpDJrnvagXKCeT7eR15YbpNR1VU1ggslack-domain-verification=dhXjQKbvU8jZaBgq87EHdETvs9GfmNpeLlkr2bsJdust-domain-verification-0x9hfb=r9ZXy9QqMfLksRIQQsDVQEG8cCKO=cli_akrcxxw2qusepg6culfktj54qagoogle-site-verification=BZ9L62F0AzxKxtItjDhylNLMb5Diy8Xa60w1MsrVy5gsendinblue-code:6efd3d137baed032a586a2bb5dbae1a64|https://www.sundayapp.comgoogle-site-verification=vVh2dglNRmbDngLppYMy_RwvTwWg_z6N-2AVRx5CpjUapple-domain-verification=r3Ekd1XC697ln1S8openai-domain-verification=dv-HT758LrInXzTmToJdQ00Me6Igoogle-site-verification=-xC2ZpaPtqa2WIuUPegzYM3QPPEBwVyE3-eDP5kTFz0proxy-ssl.webflow.com.zapier-domain-verification-challenge=bb1b5531-8fb7-4698-b995-46a8283eff27
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:_spf.salesforce.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;pct=100;rua=mailto:abuse@sundayapp.com,mailto:dmarc_agg@vali.email;fo=1;policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwXUx+xsxBb0cAXfX+o6OeUkanw4KOfrTv1CW4MgGTxqG7s1MLqrq+S/1cd7vT193WzAYTIj2pyBJA4… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed - google:
Certificate (current)
WE1
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing Referrer Policy
Header values
- permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; img-src 'self' data: https:; font-src 'self' data: https:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob:; connect-src 'self' https: wss:; upgrade-insecure-requests; block-all-mixed-content; frame-src 'self' https://www.youtube.com https://tally.so https://www.googletagmanager.com https://gtm-5jcgxhs-mju1m.sundayapp.com; report-uri https://browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub7fb364a773f0efddeb50d63ba3bc2bb1&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Asundayappcom-frontend%2Cenv%3Aproduction;- strict-transport-security
max-age=15768000; includeSubDomains