dittytoy.net

.net crawl

First seen 2026-05-30 · Last seen 2026-05-30 · ok HTTP/1.1 200 171 ms crawled 2026-05-31

NL · 136.144.135.97 · AS20857 Signet B.V.

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
Dittytoy
Description
Create your code-driven music online using a simple Javascript API. Joy is in the craft.
Language
en
Feeds

Open Graph

url
https://dittytoy.net/
title
Dittytoy
site name
Dittytoy
description
Create your code-driven music online using a simple Javascript API. Joy is in the craft.

Technology

Server
Apache
jQuery
3.5.1

Social

Registration

Registrar
Key-Systems GmbH
Created
2022-06-22
Expires
2026-06-22 20 days left
Updated
2025-11-25
Name servers
  • ns0.transip.net
  • ns1.transip.nl
  • ns2.transip.eu

DNS records live

NS
  • ns0.transip.net
  • ns1.transip.nl
  • ns2.transip.eu
MX
  • 10 dittytoy.net
Verified for
  • Google

Email authentication strong

SPF
v=spf1 a:dittytoy.net ip4:136.144.135.97 ip6:2a01:7c8:fff7:218:5054:ff:fe95:8b5c include:_spf.transip.email ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:info@dittytoy.net; ruf=mailto:info@dittytoy.net; fo=1
policy: quarantine
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-05-23 to 2026-08-21
Expires in 81 days

HTTP security headers

Header hygiene 40/100 Checked live page: https://dittytoy.net/

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data://*; worker-src 'self' blob:; font-src 'self'; style-src-elem 'self' 'unsafe-inline'; object-src 'none';

Links to (4)

Linked from (1)