visionfund.com
HTML metadata
Technology
- CMS
- Next.js
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (2)
- visionfundassetsstagesa.z19.web.core.windows.net×33
- consent.cookiebot.com×1
Contact
- Address
- 1 Circle Star Way, 94070, San Carlos, CA, US
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1999-05-19
- Expires
- 2026-05-19 0 days left
- Updated
- 2025-05-20
- Name servers
-
- ns1-09.azure-dns.com
- ns2-09.azure-dns.net
- ns3-09.azure-dns.org
- ns4-09.azure-dns.info
DNS records live
- NS
-
- ns1-09.azure-dns.com
- ns2-09.azure-dns.net
- ns3-09.azure-dns.org
- ns4-09.azure-dns.info
- TXT
-
6sqn1lrlcqywwy9p3vc1kkz5tvxbhdpz
Email authentication no MX
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 98 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' player.vimeo.com; connect-src https://sb-vf-assets.s3.amazonaws.com https://visionfundassetsstagesa.z19.web.core.windows.net https://cdn.jsdelivr.net https://unpkg.com *.typeform.com *.clarity.ms *.cookiebot.com api.lever.co *.sentry.io restcountries.com/v2/all api.hsforms.com 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com *.akamaized.net vimeo.com *.vimeo.com *.vimeocdn.com *.algolia.net *.algolianet.com; img-src *.typeform.com i.vimeocdn.com https://sb-vf-assets.s3.amazonaws.com https://visionfundassetsstagesa.z19.web.core.windows.net https://*.google-analytics.com https://*.googletagmanager.com *.usefathom.com *.clarity.ms imgsct.cookiebot.com *.bing.com 'self' data:; script-src 'unsafe-eval' 'wasm-unsafe-eval' *.typeform.com player.vimeo.com www.youtube.com https://*.googletagmanager.com www.google-analytics.com *.usefathom.com https://*.clarity.ms https://c.bing.com *.cookiebot.com 'unsafe-inline' 'self' blob:- strict-transport-security
max-age=10886400; includeSubDomains; preload