controlla.xyz

.xyz crawl

First seen 2026-04-13 · Last seen 2026-05-06 · ok HTTP/1.1 200 1265 ms crawled 2026-05-06

US · 172.67.69.182 · AS13335 Cloudflare, Inc.

Reputation 97/100 dmarc monitor-only

Classifying

HTML metadata

Title
Controlla Voice - Unleash your voice
Description
Controlla Voice is an AI singing voice generator that brings iconic and fictional voices to life, transforms vocals into choirs and instruments, and perfects pitch without vocal fatigue.
Language
en
Canonical
https://voice.controlla.xyz

Open Graph

url
https://voice.controlla.xyz
title
Controlla Voice - AI Singing Voice Generator
locale
en_US
site name
Controlla Voice
description
Controlla Voice is an AI singing voice generator that brings iconic and fictional voices to life, transforms vocals into choirs and instruments, and perfects pitch without vocal fatigue.

Technology

CDN
Cloudflare
CMS
Gatsby
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (5)

  • fonts.googleapis.com×2
  • cdn.tolt.io×1
  • fonts.gstatic.com×1
  • kit.fontawesome.com×1
  • www.googletagmanager.com×1

Registration

Registrar
Squarespace Domains II LLC
Created
2021-05-27
Expires
2026-05-27 7 days left
Updated
2025-06-18
Name servers
  • eugene.ns.cloudflare.com
  • yolanda.ns.cloudflare.com

DNS records live

NS
  • eugene.ns.cloudflare.com
  • yolanda.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • tiktok-developers-site-verification=2XblELlkICFFHK7VbVBXUKvPyi3VmfoA
Verified for
  • Google
  • Meta

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:sendgrid.net include:mail.zendesk.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:e0f8d9c0db5747bfa91212432853175e@dmarc-reports.cloudflare.net,mailto:dmarc-reports@controlla.xyz
policy: none (monitoring only)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxtmjRIiAvP9ks4Y8g4prQZUS0HT8ubAWjhx9vgJexnBf9bxPiwx4Zg+6mHLCZCgIUHE899+IM/VkFcsL6v…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArYgaf9BnENDTPIJVDZTCAojC3IDtyaGsKVcqXH+OAJ4TDMN+rUOLLvewIKWvr6MLA5+AEX6dRvyX6olKoS…
selectors probed

Certificate (current)

E8
from 2026-05-01 to 2026-07-30
Expires in 71 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://voice.controlla.xyz/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' * blob:; worker-src 'self' https://*.posthog.com blob:; style-src 'self' 'unsafe-inline' blob: https://fonts.googleapis.com https://kit.fontawesome.com https://ka-p.fontawesome.com https://*.posthog.com https://*.churnkey.co; font-src 'self' data: https://*.posthog.com https://fonts.gstatic.com https://kit.fontawesome.com https://ka-p.fontawesome.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.posthog.com https: blob:; img-src 'self' https://*.posthog.com data: https:; frame-src 'self' https://www.googletagmanager.com https://www.youtube.com https://www.youtube-nocookie.com https://*.cloudflare.com https://js.stripe.com/; frame-ancestors 'self' https://voice.controlla.xyz https://www.googletagmanager.com https://analytics.tiktok.com https://connect.facebook.net https://app.posthog.com https://www.youtube.com https://www.youtube-nocookie.com;
strict-transport-security
max-age=15552000; includeSubDomains

Linked from (2)