fleetcmd.app

.app crawl

First seen 2026-04-16 · Last seen 2026-05-07 · ok HTTP/1.1 200 1533 ms crawled 2026-05-11

US · 172.67.154.212 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
fleetCMD
Language
en

Technology

CDN
Cloudflare
Analytics
  • Cloudflare Insights

Third-party hosts loaded (1)

  • static.cloudflareinsights.com×1

DNS records live

NS
  • kianchau.ns.cloudflare.com
  • uma.ns.cloudflare.com
MX
  • 0 mx1.hc1618-31.c3s2.iphmx.com
  • 0 mx2.hc1618-31.c3s2.iphmx.com
TXT
Show 4 TXT records
  • MS=ms85396142
  • rmbr8tq5iflf9mdmpimhvn6v32
  • v=BIMI1; l=https://def0a2r1nm3zw.cloudfront.net/bimi_asset_39ff109eeca82718e1c43bb213cf1c1d.svg
  • MS=ms35498508

Email authentication strong

SPF
v=spf1 exists:%{i}._i.%{d}._d.espf.dmp.cisco.com include:%{d}.03.spf-protect.dmp.cisco.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:molson@rua.dmp.cisco.com; ruf=mailto:molson@ruf.dmp.cisco.com
policy: reject (enforced)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2sBGx9eFWxr2qykbKMqpNckHO2aTRNuYQxZv/8mWWPHfb4Wh4vV0NOklA85mGUwv6tKGcee5LJv8L9wfHk…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsCltFaQLjOCHW7uov0f2bYhZvfLADhikQuqKQppSv4IrHGWhc/WZMgPcemeGgb/WXtzxDwdyVPUGMMiFKV…
selectors probed

Certificate (current)

E7
from 2026-03-25 to 2026-06-23
Expires in 34 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://u617.fleetcmd.app/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' *.cloudflare.com 'unsafe-inline'; script-src-elem 'self' *.mapbox.com *.pendo.io *.cloudflare.com 'unsafe-inline'; worker-src 'self' blob:; media-src 'self' *.azurecontainerapps.io; img-src 'self' *.mapbox.com *.pendo.io data: blob: *.azureedge.net *.azurefd.net ; style-src 'self' 'unsafe-inline'; connect-src 'self' *.mapbox.com *.smartcmd.app *.monitor.azure.com *.pendo.io *.microsoftonline.com *.windows.net login.microsoftonline.com; font-src 'self' data:; frame-src 'self' *.microsoftonline.com *.azure.com login.microsoftonline.com *.azureedge.net *.azurefd.net ; frame-ancestors 'self' *.azure.com *.microsoftonline.com; object-src 'none';
strict-transport-security
max-age=63072000; includeSubDomains; preload

Linked from (2)