treeconomy.co
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
Third-party hosts loaded (1)
- px.ads.linkedin.com×1
Social
DNS records live
- NS
-
- ns51.domaincontrol.com
- ns52.domaincontrol.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=QVX6H7x8N_KmTOGzdig1de5-FzVrJWOGLGhiQrrRnDoMS=ms61626307apple-domain-verification=xGgFJuz89Ljy0Keq
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0KUMVWTa7tzgY0+y5wnz6pPMoG3rqzR7FojDbYwPMj7+vyY2JT8JHryCeQYLjzAG/7DjOCbGQUXay+e7II… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1PIwYvY+oE5uoLBfLp4MeTd/+ss4UggerjeP4Q6QzAZ08lGOJ3jfqUz+pG0NCTRpqViKeDS78+fSSB975g…
selectors probed - s1:
Certificate (current)
R12
Expires in 40 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing Content Security Policy
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- strict-transport-security
max-age=63072000- content-security-policy-report-only
default-src 'self'; script-src 'self' 'nonce-NWNiOWZmZGItZGUxNC00ZTkzLTlmM2QtNGZiZjUxYmE1MjY2' https://www.googletagmanager.com https://js-eu1.hs-scripts.com https://js-eu1.hscollectedforms.net https://js-eu1.hs-analytics.net https://js-eu1.hs-banner.com https://js-eu1.usemessages.com https://vercel.live; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https://images.ctfassets.net https://sherwoodprojectdata.blob.core.windows.net https://track-eu1.hubspot.com https://www.googletagmanager.com https://www.google.co.in; media-src 'self' https://sherwoodprojectdata.blob.core.windows.net https://downloads.ctfassets.net https://assets.ctfassets.net; connect-src 'self' https://graphql.contentful.com https://api.mapbox.com https://api-eu1.hubspot.com/ https://forms-eu1.hscollectedforms.net https://stats.g.doubleclick.net https://analytics.google.com; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self' https://api.hsforms.com; frame-src 'self' https://app-eu1.hu