whoop.com
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- Analytics
-
- Amplitude
- Google Tag Manager
- Cookie consent
-
- OneTrust
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (6)
- images.ctfassets.net×37
- cdn.amplitude.com×2
- cdn.cookielaw.org×2
- use.typekit.net×2
- videos.ctfassets.net×1
- www.googletagmanager.com×1
Contact
- Address
- One Kenmore Sq, 02215, Boston, Massachusettes, USA
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1996-09-17
- Expires
- 2027-09-16 485 days left
- Updated
- 2022-09-17
- Name servers
-
- ns-1478.awsdns-56.org
- ns-1687.awsdns-18.co.uk
- ns-75.awsdns-09.com
- ns-851.awsdns-42.net
DNS records live
- NS
-
- ns-1478.awsdns-56.org
- ns-1687.awsdns-18.co.uk
- ns-75.awsdns-09.com
- ns-851.awsdns-42.net
- MX
-
- 10 us-smtp-inbound-1.mimecast.com
- 10 us-smtp-inbound-2.mimecast.com
- TXT
-
Show 17 TXT records
openai-domain-verification=dv-V7rANL9FZbTtCZt5DJBvyShFshopify-verification-code=vWxLTnUetAFzc5NwTt0FQgMaX7b04Mfigma-domain-verification=731153eca1f7451cc05d9d243c8d38ad5a354438d8c258928b0105595b9b2e06-1775674672facebook-domain-verification=cv6eiirod68o6qyeronctmq7nmj3n1segment-site-verification=BduoPQxymvUa6O22ENy4f1Xx3jkokJweatlassian-domain-verification=xluRuT9acboMFh4SiluAGzw66oKLztQOvLrfNyWLGXt8JmS0EEZXlK5eJcjXv2ahpaloaltonetworks-site-verification=6ac1ce4bbe109b945db41753e67c99426d51f9594e3feb206560984456a69f7egoogle-site-verification=N2tVBJL-ws3rGzuSKxqwUjoALkDGFAGUgBo_o5xeHjcOSSRH-81963easydmarc-verification:64004933-d175-44f7-9873-02baf2648a9eapple-domain-verification=Lfq5HqhXn4XkDPQjwpe-verification=whoopinccursor-domain-verification-n8pmsc=SnZh2JXNEiM35RbvelZ4bWPH3stripe-verification=01fa267abaeaa23093636fbb7f271bcea6b9902f4f5d84311cfebed01bd4a9c4sMkrSQ5hG9kjGWRHBCktqMlBuyWGCEYDcBO3/xXtk3w=stripe-verification=913ED3594EF9E618CB6F14D026F7D0230B83B38ECA30ECE91BE7555E11F91DBFMS=ms41381868
Email authentication strong
- SPF
-
v=spf1 include:_spf.whoop_com._d.easydmarc.pro -allstrict (-all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:d191afca25@rua.easydmarc.us,mailto:dmarcreports@whoop.com;ruf=mailto:d191afca25@ruf.easydmarc.us;ri=86400;fo=1;policy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1unjzNg8lVTexUA1dDbjtL710t9g1n0HLm8/gGig/TaTtq4FVMaN7iTZVZEm6f8JEjne311NxraIWK… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDaihHg9jOtM2EVLwIYIxbFXLQDM7HSCxUcXqilsBp7Yu8CD4boQ7VTpvacU76TUrZCC6g0bPYRpdMq/Ju1Ep/GI7rmqVm…
selectors probed - google:
Certificate (current)
R12
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/* https://www.googletagmanager.com https://www.google-analytics.com; connect-src * data: https://www.googletagmanager.com https://www.google-analytics.com; style-src * 'unsafe-inline' https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/*; img-src * data: https://images.ctfassets.net; font-src * https://fonts.googleapis.com https://fonts.gstatic.com; frame-src *; frame-ancestors * https://app.contentful.com; media-src *; worker-src 'self' blob:;- strict-transport-security
max-age=63072000