tulip.co
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- Apache
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (8)
- tulip.widen.net×6
- cdn.intellimize.co×2
- 117963936.intellimizeio.com×1
- api.intellimize.co×1
- cdn.weglot.com×1
- js.qualified.com×1
- log.intellimize.co×1
- www.googletagmanager.com×1
Social
Contact
- Address
- 561 Windsor Street b204, 02143, Somerville, Massachusetts, US
DNS records live
- NS
-
- ns-1065.awsdns-05.org
- ns-1756.awsdns-27.co.uk
- ns-341.awsdns-42.com
- ns-953.awsdns-55.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 13 TXT records
google-site-verification=PUusOsepp30MwHZ0Lb31ias-xq_rufDrzhvVvVhUAVwgoogle-site-verification=R8RVvVyZkF0AYVX5n0vbn0_loJKCk7Jz63XxFG6LXtgmongodb-site-verification=vKsfGdhnpYHOvkEprHGHSeJ9BfG2AaQgopenai-domain-verification=dv-aY7gYcdNcXpT09NkmrzRNTAIMS=060A8480D932A640C3BBBE21A9954E2F39E4E560MS=ms32849905TAILSCALE-u4wtQsiRbUi4C0hzk3LMadobe-idp-site-verification=4a152dfba702a160cb122e9ce5333f687fca0b74c365d3760dfbf56e79cb1fdeapple-domain-verification=ThJjUTwt0JhjVOWpatlassian-domain-verification=dp9GK8hXz6GTKBGn5z2WNbJQIsidYrLrr5efxl47EKZOaqMF3JQ7qzGB3BjQH12Patlassian-sending-domain-verification=871afe34-df1c-48bf-8e39-4ed924f15fc2google-site-verification=-IVFY1AWPSq8ehuIZphfUj9izer8e6zB9IvK0VawCb4google-site-verification=C_w-eJF3SeTNnOz2-PJz-MYVBPLApROWV7txwM8iu5A
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com include:mktomail.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:sysadmin+dmarc@tulip.co; ruf=mailto:sysadmin+dmarc@tulip.co; fo=1;policy: reject (enforced) - DKIM
-
Show 5 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnJSOn4ui7AQUW80mvKp1fX0KykSFiKOgfq5EFnUUqS5W5UPIqExifjBPPMbj9FxBPwSklqeb0uy/NJ… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt4B7Bqffhk2NK38qNm2i0NLY8+6PlU9ioSMWKwJSCvPzDHN/OdngLn2AK94FqTmbOSh2SormV8WedmFXJs… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDXpvWI4+PgkXVJzOviH/iNwG0d1DYZPKk9I7jtNhMmmhADCJ/CjfxCO9PXj8HMcKL5Wno0MGgDCivaPaeUZue5sb… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 183 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
geolocation=(), midi=(), sync-xhr=(), accelerometer=(), gyroscope=(), magnetometer=(), camera=(), fullscreen=(self "https://*.matterport.com" "https://tulip.widen.net" "https://*.youtube.com" "https://youtube.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:; font-src https: data: https://fonts.gstatic.com; img-src 'self' https: data: https://v2assets.zopim.io https://static.zdassets.com https://www.google-analytics.com https://www.googletagmanager.com https://optimize.google.com https://d1g11qfvmedxbq.cloudfront.net/; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://api.intellimize.co https://cdn.intellimize.co *.tulip.co player.fireside.fm tag.clearbitscripts.com tulip.co tulip.ups.dock wss://tulip.zendesk.com wss://*.zopim.com https://googleads.g.doubleclick.net https://region1.google-analytics.com https://*.google-analytics.com https://*.googletagmanager.com https://*.googleadservices.com https://*.google.de https://*.google.com https://*.google.fr https://*.google.es https://tracking.g2crowd.com https://td.doubleclick.net https://*.doubleclick.net https://*.ketchcdn.com https://*.ketchjs.com https://www.facebook.com https://*.facebook.net https://px.ads.linkedin.com https://edge.fulls- strict-transport-security
max-age=63072000; includeSubDomains