congobet.net

.net toplist

First seen 2026-04-11 · Last seen 2026-04-11 · ok HTTP/1.1 200 1215 ms crawled 2026-05-18

NL · 23.97.219.13 · AS8075 Microsoft Corporation

Reputation 92/100 no dmarc policy

Classifying

Technology

Server
Microsoft-IIS
Fonts
  • Google Fonts

Third-party hosts loaded (2)

  • fonts.googleapis.com×2
  • fonts.gstatic.com×1

Registration

Registrar
Gandi SAS
Created
2016-07-03
Expires
2026-07-03 44 days left
Updated
2025-06-13
Name servers
  • ns-180-c.gandi.net
  • ns-199-a.gandi.net
  • ns-9-b.gandi.net

DNS records live

NS
  • ns-180-c.gandi.net
  • ns-199-a.gandi.net
  • ns-9-b.gandi.net
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 4 TXT records
  • google-site-verification=TujHGsD3HGLDsk-y8GmENjQVcCOkX6JKOrlmFC02u2o
  • MS=ms16106702
  • google-site-verification=XBLTP5ZnLEiq43zU9qIqPIPTLCy2OvrlAHnbvMGjd98
  • hg-congobet-portal-web-prod.azurewebsites.net

Email authentication weak

SPF
v=spf1 include:_spf.google.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

GandiCert
from 2025-09-12 to 2026-09-13
Expires in 116 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://congobet.net/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
geolocation=(), camera=(), microphone=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; style-src 'self' * 'unsafe-inline';style-src-attr 'self' 'unsafe-inline' *; style-src-elem 'self' 'unsafe-inline' blob: *; font-src 'self' *; script-src 'self' 'unsafe-eval' 'unsafe-inline' *; connect-src *; img-src 'self' 'unsafe-inline' data: blob: *; manifest-src *; frame-src *; media-src * blob:; worker-src 'self' blob:
strict-transport-security
max-age=31536000; includeSubDomains; preload