yola.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (6)
- player.vimeo.com×6
- cdn.sitebuilderhostqa.net×1
- f.vimeocdn.com×1
- i.vimeocdn.com×1
- static.cloudflareinsights.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- SafeNames Ltd.
- Created
- 2001-06-11
- Expires
- 2026-06-11 22 days left
- Updated
- 2024-07-01
- Name servers
-
- coby.ns.cloudflare.com
- nola.ns.cloudflare.com
DNS records live
- NS
-
- coby.ns.cloudflare.com
- nola.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 5 TXT records
facebook-domain-verification=5k0fwqain2egf1d86bbza9dakd124ygoogle-site-verification=7qEjMTJB_QiK6W0ztBkpM41tZ0c_-czWyUWZ5XqY8D4google-site-verification=l04y2pna-nw-94rWNP_6aevn3rLXdFZUJVxkNGde3K8site24x7-signals-domain-verification=f1854e19b98d649e470290ccd007241aMS=ms73446291
Email authentication strong
- SPF
-
v=spf1 ip4:74.112.67.187 include:_spf.google.com include:registrarmail.net include:mail.zendesk.com include:sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1; p=none; pct=100; rua=mailto:ba097ceccad7447@rep.dmarcanalyzer.com; ruf=mailto:ba097ceccad7447@for.dmarcanalyzer.com; fo=1policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnEuxNQETmvMgFKGXWiq3vr+tF71gdvDkOHde8K2EaNlUqEfPd97ZsAWcrD2UB9H46K8JUXFcowCGsB… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0K/3v40umhBK4qhiYS7EoeCnhG8sjG7usw8R0kzVMK9w90uHKHBdraZcJHJZDmEO/0z1e6VB3Jdvmf5vpH… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqpsPzGWDk0EDgzbNbMCRrT6dzwjQw2z8QL+XKlparEPzB8rjYstgyNN6oOmHNLgVWMrXzrprKmCuMElvJX…
selectors probed - google:
Certificate (current)
WE1
Expires in 22 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'unsafe-inline' 'unsafe-eval' 'self' *.cloudflare.com www.yola.com unpkg.com *.yolacdn.net cdn.ravenjs.com *.googleapis.com *.sharethis.com www.googleoptimize.com www.googletagmanager.com *.googleusercontent.com *.gstatic.com secure.gravatar.com www.facebook.com www.google-analytics.com *.google.com *.yola.net *.yola.com *.yolaqa.com *.storylane.io *.vimeo.com *.player.vimeo.com *.vimeocdn.com *.f.vimeocdn.com *.i.vimeocdn.com jitter.video stats.g.doubleclick.net *.fullstory.com s.w.org *.sitewit.com *.wikimedia.org www.youtube.com wp-themes.com *.sitebuilderhostqa.net *.contentsquare.net *.plerdy.com data: blob:;frame-ancestors 'self'; form-action 'self';- strict-transport-security
max-age=63072000; preload