cpbrandsite.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (2)
- cdn-app.cp-cmpd.com×1
- static.cloudflareinsights.com×1
Social
Contact
- Phone
Registration
- Registrar
- DotArai Co., Ltd.
- Created
- 2008-01-14
- Expires
- 2029-01-14 956 days left
- Updated
- 2019-02-11
- Name servers
-
- pam.ns.cloudflare.com
- rick.ns.cloudflare.com
DNS records live
- NS
-
- pam.ns.cloudflare.com
- rick.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Kd6FOguo0dvuOMYuSZThd9EUs1ybf6noZ109LlkfQn4
- Verified for
-
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 48 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
ALLOW-FROM https://game.cpbrandsite.com- permissions-policy
accelerometer=(self "https://www.youtube.com"),autoplay=(self "https://www.youtube.com"),camera=(),clipboard-write=(self "https://www.youtube.com"),document-domain=(),encrypted-media=(self "https://www.youtube.com"),fullscreen=(),geolocation=(),gyroscope=(self "https://www.youtube.com"),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(self "https://www.youtube.com"),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(self "https://www.youtube.com"),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
block-all-mixed-content; connect-src 'self' *.cpbrandsite.com *.algolianet.com *.algolia.net *.amplitude.com *.clarity.ms cdnjs.cloudflare.com cloudflareinsights.com *.doubleclick.net www.facebook.com/privacy_sandbox/topics/registration/ www.facebook.com/tr/ www.google.co.th/ads/ga-audiences *.google-analytics.com *.googleapis.com analytics.google.com *.googletagmanager.com cdn.jsdelivr.net *.segment.com *.segment.io *.tealiumiq.com *.tiqcdn.com *.tiqcdn.cn *.tiktok.com *.tiktokw.us *.webtrendslive.com; default-src 'self' ; form-action 'self' www.facebook.com/tr/; font-src 'self' data: cdnjs.cloudflare.com fonts.gstatic.com; frame-ancestors 'self' game.cpbrandsite.com; frame-src 'self' *.tiktok.com *.doubleclick.net *.facebook.com *.google.com *.twitter.com *.youtube.com; img-src 'self' blob: data: * *.cp-cmpd.com c.bing.com c.clarity.ms cdnjs.cloudflare.com *.facebook.com *.google-analytics.com storage.googleapis.com www.google.co.th/ads/ga-audiences *.googletagmanager.com *.w- strict-transport-security
max-age=31536000; includeSubdomains; preload- cross-origin-opener-policy
same-origin; report-to="default";- cross-origin-embedder-policy
require-corp; report-to="default";- cross-origin-resource-policy
same-site