broodnet.com
HTML metadata
Social
Contact
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2026-02-09
- Expires
- 2027-02-09 266 days left
- Updated
- 2026-02-11
- Name servers
-
- coco.ns.cloudflare.com
- piotr.ns.cloudflare.com
DNS records live
- NS
-
- coco.ns.cloudflare.com
- piotr.ns.cloudflare.com
- MX
-
- 10 mail.broodnet.com
- TXT
-
gridinsoft-verify=52fdxdouzvbgk6s7l346rf0vh0zkql8pyw4423ct2axqlck07k5l2aute9vgy05tyandex-verification: a4c097bbf7abede5google-site-verification=40h11Lm_1scVDJ1DflVoNzOEDNZUXCiNfWoXN7TOrhg
Email authentication strong
- SPF
-
v=spf1 mx -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:postmaster@broodnet.compolicy: reject (enforced) - DKIM
-
- dkim:
v=DKIM1;k=rsa;t=s;s=email;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvRD1POt1GvHYJ7qcdNrlXloczqwppyPTbjuiyJtMy8Viujfas2mjyBKjYfd5RIxZ9Fiq…
selectors probed - dkim:
Certificate (current)
E8
Expires in 63 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), autoplay=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), gamepad=(), hid=(), idle-detection=(), microphone=(), payment=(), picture-in-picture=(), screen-wake-lock=(), serial=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' stats.broodnet.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: www.gravatar.com avatars.githubusercontent.com *.googleusercontent.com opengraph.githubassets.com meli-email.org alpineapp.email; connect-src 'self' api.broodnet.com stats.broodnet.com; font-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; frame-src 'none'; manifest-src 'self'; object-src 'none'; upgrade-insecure-requests;- strict-transport-security
max-age=31536000; includeSubDomains; preload