wealthtender.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
Third-party hosts loaded (2)
- gmpg.org×1
- px.ads.linkedin.com×1
Social
Contact
- Phone
Registration
- Registrar
- Name.com, Inc.
- Created
- 2019-02-07
- Expires
- 2034-02-07 2820 days left
- Updated
- 2025-07-24
- Name servers
-
- carlos.ns.cloudflare.com
- isla.ns.cloudflare.com
DNS records live
- NS
-
- carlos.ns.cloudflare.com
- isla.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
astra-target-verification=384d510111e8c66b9fc1d36e751a9ebdf135be35a653901d7aaf9d0bca30058bfacebook-domain-verification=sjffjl5y7moldzxbm5d02m8k0osndcgoogle-site-verification=vOGJxbn_r-1iluFbI-uoad6b7cH_2fJ5GPrCYcL7bXIgoogle-site-verification=y0rYsVcneCuQrkOUSX-wm4vzBzi56f7mQIUyDbhZe8Ilinkedin-site-verification=291ec361-067c-46e9-b2c4-e899167b65bdprowly-verification=8784267ec1c53b245bb82693cd04df18ce0af17197aab7e7b70bc89a17550bc5
Email authentication partial
- SPF
-
v=spf1 include:mailgun.org include:6125013.spf06.hubspotemail.net include:_spf.createsend.com include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:d8994c6179c44b33b5017ccc8210da56@dmarc-reports.cloudflare.net;policy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsrrSFnNT1CLc2lI4vdCTHFjQDOfBy9knGSaFm6yZFL6ZqX0vY9o6TEAjm882QALp6pgKxA+j9ydVV1… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuVUS6QgR6M02ing/WBZO6H9nACDHiMrspkfmVS3DM208V2UU0rrLeAdogbdMO9S91RdctLHq42etg2WQsy… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCz2pE5Ao/OhnWqUy4/vcZkASXU8fw06XC7GKU3B2KwmG047DGe4cjUvjDcY3hYIka0MZ+aDJdFLNRjmtlDcmtnG… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - google:
Certificate (current)
E8
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=(), speaker-selection=(), conversion-measurement=(), focus-without-user-activation=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), sync-script=(), trust-token-redemption=(), window-placement=(), vertical-scroll=()- x-content-type-options
nosniff- content-security-policy
default-src * self blob: data: gap:; style-src * self 'unsafe-inline' blob: data: gap:; script-src * 'self' 'unsafe-eval' 'unsafe-inline' blob: data: gap:; object-src * 'self' blob: data: gap:; img-src * self 'unsafe-inline' blob: data: gap:; connect-src self * 'unsafe-inline' blob: data: gap:; frame-src * self blob: data: gap:;- strict-transport-security
max-age=31536000- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin