veriff.com
HTML metadata
Technology
- Server
- Off
- CMS
- WordPress
- Analytics
-
- Amplitude
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (13)
- spcdn.shortpixel.ai×114
- cdnjs.cloudflare.com×9
- cdn.jsdelivr.net×7
- unpkg.com×5
- cdn-cookieyes.com×3
- dev.visualwebsiteoptimizer.com×3
- www.googletagmanager.com×3
- cdn.plyr.io×2
- fonts.googleapis.com×2
- cdn.eu.amplitude.com×1
- fonts.gstatic.com×1
- gmpg.org×1
- js.hsforms.net×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2006-04-12
- Expires
- 2028-04-12 694 days left
- Updated
- 2023-04-12
- Name servers
-
- ns-1214.awsdns-23.org
- ns-1766.awsdns-28.co.uk
- ns-475.awsdns-59.com
- ns-632.awsdns-15.net
DNS records live
- NS
-
- ns-1214.awsdns-23.org
- ns-1766.awsdns-28.co.uk
- ns-475.awsdns-59.com
- ns-632.awsdns-15.net
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 11 TXT records
verification=_dx1pFkYIoEdpyApLp_8wWNAkMvf15yCj2TPhIrsDuA2gqqootrlu2e71f33kj5972birZOOM_verify_2L7hKeXzX8ONukya69ekllatlassian-domain-verification=+lkxdTi+vjM5+c4tHzmrP3GlIkn5HXJ/y05A2BaXt961sJhIcEOHqc6ObDQShPV2docusign=71e79182-561b-455f-a28d-e7880c7dbb64google-site-verification=7mFw7tRr5SHPtCnKjkq7g2htLJqZw9DDG_0wlsNJ0pkgoogle-site-verification=EK-MtoC0IOkhxP7pi6cJkFR_RjSpbTCphfy5m8PkeBsgoogle-site-verification=Rfs6N7awEjQMyF0GjYOennPilFoWYEiP3osZhORUODImiro-verification=733dc17c529c67ac39db0960e239c130127dc2d6postman-domain-verification=5b06a833b4dc8306b49d7c97c5ebb2c2ce22e3a46a50f8346db33555933251ada34a8d90b8029bc904ff456881b00161d04bc5c61af931c6a5f9f69c740ebd99stripe-verification=792545d636567b2278cf8ae2d82aa7992092ccf5d1f0b3981149835388384102
Email authentication strong
- SPF
-
v=spf1 include:mail.zendesk.com include:_spf.google.com include:9051673.spf10.hubspotemail.net include:sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:8ff23af79e@rua.easydmarc.eu;ruf=mailto:8ff23af79e@ruf.easydmarc.eu;fo=1policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCaCgYoM39EqEY6dCQyCLy+kWOJaD9HORT70lljLTqDC7yPnSZklDl+tYwR8z32sQU97A+x9GeXfc5CoEI5V+… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA75LE+MUzoTq072j757mUyC5DtgtIAVF6mjnxMokEZ78wsF8MFHZl0mvNXshR3BTp3PDqNYH75rqczV7fn3… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCyKJJARLz/3FL/AI2o0AXIOSaPNbFmSBjdQG8fVEVg+tCvYRKv4zOd9UZu0bgrzoG1LobNdmdkaD6l0BW6n3oBce…
selectors probed - google:
Certificate (current)
R13
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
camera=(self 'https://veriff.com' 'https://*.veriff.com'), geolocation=(), microphone=(self 'https://veriff.com' 'https://*.veriff.com'), sync-xhr=()- x-content-type-options
nosniff- content-security-policy
default-src * blob: data: https:; script-src blob: https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'- strict-transport-security
max-age=31622400; includeSubDomains; preload