hellocue.app

.app crawl

First seen 2026-06-02 · Last seen 2026-06-02 · ok HTTP/1.1 200 431 ms crawled 2026-06-02

US · 99.86.109.21 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Hello Cue
Language
en

Technology

CDN
Amazon CloudFront
Server
AmazonS3

DNS records live

NS
  • ns1.dnsimple-edge.com
  • ns2.dnsimple-edge.net
  • ns3.dnsimple-edge.io
  • ns4.dnsimple-edge.org
MX
  • 0

Email authentication weak

SPF
not published
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

Amazon ECDSA 256 M01
from 2025-12-03 to 2027-01-02
Expires in 211 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://hellocue.app/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; object-src 'none'; font-src 'self' child-src 'none'; frame-src 'self' blob:; manifest-src 'none'; media-src 'self'; prefetch-src 'self'; form-action 'none'; img-src 'self' data:; connect-src 'self' cognito-idp.us-east-1.amazonaws.com *.execute-api.us-east-1.amazonaws.com; base-uri https://hellocue.io https://*.hellocue.app; frame-ancestors 'none'; upgrade-insecure-requests
strict-transport-security
max-age=31536000; includeSubDomains

Linked from (1)