zaiko.io
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- Nuxt
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×3
- cdn.jsdelivr.net×1
- fonts.gstatic.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ns-1376.awsdns-44.org
- ns-1889.awsdns-44.co.uk
- ns-396.awsdns-49.com
- ns-670.awsdns-19.net
- MX
-
- 1 aspmx.l.google.com
- 10 aspmx2.googlemail.com
- 10 aspmx3.googlemail.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 18 TXT records
stripe-verification=f0ece7ade369c98f1302c54d56c5bb1424ad085818e3a073b3ba944f1f0a5cfddocusign=4e64b375-e2ce-41a4-b6bf-0a266f4e6705stripe-verification=4dea2f49062399eb65737b7422a61b268dfd0463c05e2dcceb1c2174dd2999dagoogle-site-verification=41FHBkafljVjG7h7N1MNbCJ35W_oZ4eqbdXdoY0DhhIstripe-verification=295b0309447c6b2784b0128437c63fdc62c93586911145dfd4fae50fa549d4e4stripe-verification=e566c444ac01dd22972ce4d0d5cec6a998b2a1398349e5fce0f2101feadce9fcMS=ms59607771v=spf1 include:_spf.google.com include:sendgrid.net include:_spf.smtp.mailtrap.live ~allfacebook-domain-verification=1ohnmduyeacfvv14n1ccx7w457fnt3google-site-verification=s1d86x-vOe9pHYHJ7dEcW-q4yfIHAwYoCBQpVD9DQSshcp-domain-verification=90b2b7fe93b7c9ef1523180f84ce070a090353fa3a552c6f8b4a1335fc6b7e42stripe-verification=3d3e37dd486eec1328a172cd4bddaf17be9c469cdee8eb30b1ea80fbcff99b9dopenai-domain-verification=dv-CxpmtMK1IUlkZUDUfX78ZQITstripe-verification=7541b35760ac8d65fad0490ad53c3a3d8d73d496e96092c6f57529a3ed89d45aO1JbrQ7S0erSGczsPrwBtkL66cJnapple-domain-verification=PBUBBbHz5xCqDGdjanthropic-domain-verification-0q1fvr=p6OdLL3GIjJkROlxDpITIG3Osstripe-verification=efe8d4b580ccf8fbe73e517c1d4113e19b3081f850fe1e9d296d437731a0ed6b
Certificate (current)
Amazon RSA 2048 M04
Expires in 118 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests;object-src 'none';script-src 'nonce-DAWAxu3z83L89rW9emtcHeoXfWNaEwFjC8z4nq6p' 'self' 'unsafe-inline' 'strict-dynamic' https:;base-uri 'none'- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin