sustainalytics.com

.com crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 817 ms crawled 2026-05-30

US · 104.18.201.41 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Home - Sustainalytics
Description
Morningstar Sustainalytics is a leading independent ESG and corporate governance research, ratings and analytics firm that supports investors around the world.
Language
en
Canonical
https://www.sustainalytics.com

Open Graph

url
https://www.sustainalytics.com
title
Home - Sustainalytics
site name
sustainalytics.com
description
Morningstar Sustainalytics is a leading independent ESG and corporate governance research, ratings and analytics firm that supports investors around the world.

Technology

CDN
Cloudflare
JS framework
React
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • cdn.insight.sitefinity.com×1
  • js.hs-scripts.com×1
  • www.googletagmanager.com×1

Social

Registration

Registrar
MarkMonitor Inc.
Created
2008-07-23
Expires
2027-07-23 417 days left
Updated
2025-06-21
Name servers
  • dns1.p04.nsone.net
  • dns2.p04.nsone.net
  • dns3.p04.nsone.net
  • dns4.p04.nsone.net
  • pdns205.ultradns.biz
  • pdns205.ultradns.com
  • pdns205.ultradns.net
  • pdns205.ultradns.org

DNS records live

NS
  • dns1.p04.nsone.net
  • dns2.p04.nsone.net
  • dns3.p04.nsone.net
  • dns4.p04.nsone.net
  • pdns205.ultradns.biz
  • pdns205.ultradns.com
  • pdns205.ultradns.net
  • pdns205.ultradns.org
MX
  • 5 sustainalytics-com.mail.protection.outlook.com
TXT
  • rovag_verification_token=4551D9908C234E9AB862B8FBEEB3E4D6
Verified for
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 ip4:40.114.144.140 ip4:139.138.59.195 ip4:139.138.47.72 include:spf.protection.outlook.com include:6822252.spf05.hubspotemail.net ~all
softfail (~all)
DMARC
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
policy: none (monitoring only)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrsWf7mTiAXRarxJFKM//wYR77oY0EPVr/euQQ1JCov04CX3Q6XVyQISt3pLpiqe67svnP4yCpZVgE3uYMF8…
  • smtpapi: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed

Certificate (current)

WE1
from 2026-04-10 to 2026-07-09
Expires in 38 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.sustainalytics.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • weak frame protection
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
ALLOW-FROM https://app.socio.events
x-content-type-options
nosniff
content-security-policy
default-src 'self' sustainalytics.susc4318.eas.morningstar.com https://*.hubspot.com https://*.hubspot.io https://*.hubapi.com https://*.hsforms.com https://*.hotjar.com https://*.hotjar.io https://s3.console.aws.amazon.com https://*.bizible.com *.newrelic.com https://*.nr-data.net https://*.morningstar.com; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com cdnjs.cloudflare.com 'unsafe-inline' 'unsafe-eval' sustainalytics.susc4318.eas.morningstar.com *.google.com *.googletagmanager.com *.googleadservices.com https://snap.licdn.com/ https://syndication.twitter.com http://platform.stumbleupon.com https://cdn.insight.sitefinity.com https://dec.azureedge.net munchkin
strict-transport-security
max-age=31536000; preload

Links to (8)

Linked from (2)