thatch.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-15 · ok HTTP/1.1 200 670 ms crawled 2026-05-07

US · 216.150.1.1 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Thatch | Modern Health Benefits Platform
Description
Thatch is an all-in-one platform that makes it easy to offer the most personalized healthcare experience to your employees using an ICHRA.
Language
en
Canonical
https://thatch.com/

Open Graph

url
https://thatch.com
title
Thatch | Modern Health Benefits Platform
site name
Thatch
description
Thatch is an all-in-one platform that makes it easy to offer the most personalized healthcare experience to your employees using an ICHRA.

Technology

CDN
Vercel
CMS
Next.js
Analytics
  • Google Tag Manager

Third-party hosts loaded (1)

  • www.googletagmanager.com×1

Social

Contact

Email
Address
st centerContactContact salesContact support©2026

Registration

Registrar
NameCheap, Inc.
Created
1997-07-24
Expires
2026-07-23 64 days left
Updated
2025-04-25
Name servers
  • austin.ns.cloudflare.com
  • gracie.ns.cloudflare.com

DNS records live

NS
  • austin.ns.cloudflare.com
  • gracie.ns.cloudflare.com
MX
  • 1 smtp.google.com
TXT
Show 14 TXT records
  • ZOOM_verify_MZ9AuylWYhNjmNgRtRtzLo
  • _ns9syjlerqwx6itnmd1etsc3n1vk5kz
  • apple-domain-verification=MG2ekKaRzCiLvrM2
  • figma-domain-verification=5869892aaccc826a75bbbbf31356f552c334fa2c036963b79a10e52f3801c362-1765932442
  • google-site-verification=J20DL_QLRNdm-MXI_Io-02M8zhOBQalfxvy24d_d3FA
  • google-site-verification=lshOcid7th86JYPwCex-DnhMYFHh70gusdIN6Vx5r18
  • google-site-verification=wPgwWcBvpPv3djRn59gT_5phxP2kcWUacBcPuZqXAt0
  • notion-domain-verification=419d7WCfSFR6lNsVjl33mUBwnf8dX3M7iG3pgTzi2yZ
  • openai-domain-verification=dv-FB4IgwjinhXf6zNLcCqgutdC
  • openai-domain-verification=dv-uBgBU2b9zRF4O1khgu82aNV9
  • rippling-domain-verification=5359e468b93aa4f7
  • slack-domain-verification=m2UXUXcMcHaYD5fv4Falms04tXOYNXzOaelZmzSm
  • stripe-verification=3ff00d00ecb251ad833a3ab311d141d80fe62ed486baf3b26e42019d389736f3
  • 00DHs000000QTIO=1TBTN000000015l

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:sendgrid.net include:mail.zendesk.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; aspf=r; adkim=r; rua=mailto:ce73b879e68245ba9a6dea7dc2186b6d@dmarc-reports.cloudflare.net
policy: quarantine
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAspnbj74/fOwGIgVYX0imUMred84UcGx0FVdoF0kFfUoEektKEIfqmqMf4tQhIG3DJoaRecpW+KsM+P…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuSY5lkZRhZVkRWTqnSp5sX1AS8kKChUiJu65TsdsRtB2ltKJRVu838o5ljnb/enfkJEFilw1Itk2JnWyPI…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmfRXA7o3O1aW0SckWln4soPo9hjQde4wWKvvmCz4UoX3Lu4ZjUUmNGaO61lSEvc/v59zImzwpHv+JoN5qD…
selectors probed

Certificate (current)

R13
from 2026-05-05 to 2026-08-03
Expires in 75 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://thatch.com/

present
  • strict-transport-security
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • missing Content Security Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
geolocation=(), microphone=(), camera=()
x-content-type-options
nosniff
strict-transport-security
max-age=63072000
content-security-policy-report-only
default-src https://app.thatch.com 'self'; style-src https://vercel.live *.wistia.com 'self' 'unsafe-inline' blob:; script-src https://vercel.live https://snap.licdn.com https://connect.facebook.net www.googletagmanager.com thatch.chilipiper.com ph.thatch.com *.posthog.com analytics.ahrefs.com *.wistia.com *.wistia.net src.litix.io *.sentry-cdn.com https://s3-us-west-2.amazonaws.com/b2bjsstore/b/1VN080HGQP6J/reb2b.js.gz https://www.redditstatic.com/ads/pixel.js bat.bing.com/bat.js https://bat.bing.com/p/action/187118839.js https://assets.apollo.io/micro/website-tracker/tracker.iife.js https://r2.leadsy.ai/tag.js https://osai-cdn.onescreen.ai/pscript/1.0.0.js https://www.clarity.ms/tag/uet/187118839 https://www.clarity.ms/tag/qiqp2ius59 scripts.clarity.ms https://app.factors.ai/assets/factors.js https://googleads.g.doubleclick.net 'self' 'sha256-PIWffdGzM66heRBliv6r8Z3n4xuS0tlmVLmbHNtXZbQ=' 'sha256-wJ/VhlfH39kSu+BUOiDUF8St0im8Yyu43jwgH3bfluo=' 'sha256-fVrJk5820gphjtu2OG1kC0pGiAuuOAK2ogh

Links to (11)

Linked from (3)