boredapeyachtclub.com

.com crawl

First seen 2026-04-13 · Last seen 2026-05-20 · ok HTTP/1.1 200 494 ms crawled 2026-05-07

US · 172.66.40.250 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Bored Ape Yacht Club
Description
Welcome to the Bored Ape Yacht Club — a collection of unique digital collectibles.
Language
en

Open Graph

url
https://boredapeyachtclub.com
title
Bored Ape Yacht Club
locale
en_US
site name
Bored Ape Yacht Club
description
Welcome to the Bored Ape Yacht Club — a collection of unique digital collectibles.

Technology

CDN
Cloudflare
CMS
Next.js
Analytics
  • Cloudflare Insights

Third-party hosts loaded (2)

  • banana.yuga.com×1
  • static.cloudflareinsights.com×1

Social

Registration

Registrar
MarkMonitor Inc.
Created
2021-03-30
Expires
2032-03-30 2140 days left
Updated
2025-02-26
Name servers
  • poppy.ns.cloudflare.com
  • rajeev.ns.cloudflare.com

DNS records live

NS
  • poppy.ns.cloudflare.com
  • rajeev.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 4 TXT records
  • 037a02b5-4302-4b46-9744-7b195ed9d9a8=895b5fe070b4b3653d1e8ff082539097b784542abb9d18523b82d0967ed36279
  • b32479a5-e45d-4546-bd69-91fe14b5d2d6=895b5fe070b4b3653d1e8ff082539097b784542abb9d18523b82d0967ed36279
  • hosting-site=bayc-dd759
  • klaviyo-site-verification=SNfqH9
Verified for
  • Google
  • Meta

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:mail.zendesk.com ~all
softfail (~all)
DMARC
v=DMARC1;p=none
policy: none (monitoring only)
DKIM
Show 12 DKIM selectors
  • default: v=DKIM1; p=
  • google: v=DKIM1; p=
  • selector1: v=DKIM1; p=
  • selector2: v=DKIM1; p=
  • k1: v=DKIM1; p=
  • k2: v=DKIM1; p=
  • mail: v=DKIM1; p=
  • dkim: v=DKIM1; p=
  • s1: v=DKIM1; p=
  • s2: v=DKIM1; p=
  • mxvault: v=DKIM1; p=
  • smtpapi: v=DKIM1; p=
selectors probed

Certificate (current)

E8
from 2026-04-16 to 2026-07-15
Expires in 55 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://boredapeyachtclub.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
permissions-policy
camera=(), microphone=(), geolocation=(), interest-cohort=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' https: wss: data: blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdn.jsdelivr.net https://banana.yuga.com https://static.cloudflareinsights.com https://www.youtube.com https://s.ytimg.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://cdn.sanity.io https://assets.boredapeyachtclub.com https://media.yuga.com https://3dmodels.boredapeyachtclub.com https://static.seadn.io https://res.cloudinary.com https://ipfs.io https://placehold.co https://explorer-api.walletconnect.com https://avatars.jams.bio https://*.walletconnect.com https://*.walletconnect.org https://*.metamask.io https://cdn.shopify.com https://i.ytimg.com https://yt3.ggpht.com; font-src 'self'; connect-src 'self' https://eth-mainnet.g.alchemy.com https://eth.llamarpc.com https://eth.merkle.io https://*.infura.io wss://*.walletconnect.com wss://*.walletconnect.org https://*.walletconnect.com https://*.walletconnect.org https://*.web3modal.com https://*.web3modal.org http
strict-transport-security
max-age=15552000; includeSubDomains; preload
cross-origin-resource-policy
same-origin

Links to (3)

Linked from (4)