crestron.io

.io crawl

First seen 2026-04-21 · Last seen 2026-05-15 · ok HTTP/1.1 200 5343 ms crawled 2026-05-15

US · 40.121.221.52 · AS8075 Microsoft Corporation

Reputation 100/100

Classifying

HTML metadata

Title
Crestron XiO Cloud
Language
en

DNS records live

NS
  • pdns81.ultradns.biz
  • pdns81.ultradns.com
  • pdns81.ultradns.net
  • pdns81.ultradns.org
TXT
Show 8 TXT records
  • _u9vruct99s44fsurz65rak4atn3rky0
  • _xl5o1s4lvlmo9yjdy1id4fsoki78hli
  • 4757-67D4-EDC9-1339-2641-129B-2D9C-FA89
  • google-site-verification=A4ePJhujyOtSJ34ps8QsUKltidHfKujyLSajzRpf9Sk
  • MS=ms99008059
  • _1ydibov0gmp2nvw743pk6givre4juhi
  • _36na5i395xugs6zbmugkizrqm4zbxu6
  • _pfccsffc0rabp9ab2aooml3rduq0lw7

Email authentication no MX

SPF
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;
policy: reject (enforced)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8Vimkj5qTrkDLQ2wQbR/bC1CS6QnU2slf+r6I2faioZDRvINK9jwulbQi1iDP59gvkK5kw8pTKHoKMEtti…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9tyNP8ClBxjQyRNV4buwHWcswINEZDQC1jhbesyS0xNtDbJnYeifl3sgiF8CujD3rtrRMxxirIHPK9XgWSbw0j1…
selectors probed

Certificate (current)

Thawte TLS RSA CA G1
from 2026-01-27 to 2027-02-24
Expires in 281 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://crestron.io/login

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
connect-src 'self' https://*.azurewebsites.net https://*.crestron.io https://*.crestron.com https://drivers-api.crestron.io https://*.blob.core.windows.net https://*.datadoghq.com https://browser-intake-datadoghq.com https://browser-intake-us3-datadoghq.com https://browser-intake-us5-datadoghq.com https://*.b2clogin.com https://*.onmicrosoft.com https://*.microsoftonline.com https://*.microsoft.com; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src * data: blob:; font-src 'self' data: https://*.crestron.com https://*.crestron.io https://fonts.gstatic.com https://fonts.googleapis.com; frame-src 'self' https://*.b2clogin.com https://*.onmicrosoft.com https://*.microsoftonline.com https://*.powerbi.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none';
strict-transport-security
max-age=31536000; includeSubdomains

Linked from (2)