hepalink.com
HTML metadata
Technology
- Server
- Microsoft-IIS
Third-party hosts loaded (1)
- cdn.bootcss.com×1
Registration
- Registrar
- Xiamen 35.com Information Co., Ltd.
- Created
- 2000-12-22
- Expires
- 2027-12-22 581 days left
- Updated
- 2025-06-08
- Name servers
-
- f1g1ns1.dnspod.net
- f1g1ns2.dnspod.net
DNS records live
- NS
-
- f1g1ns1.dnspod.net
- f1g1ns2.dnspod.net
- MX
-
- 5 hepalink-com.mail.protection.outlook.com
- TXT
-
google-site-verification=iZ9318WxqZB_jyRJGioRoudMOtSjbyZlzIe_6KDu7LYMS=ms97857003google-site-verification=BeJ_wOaJqB-vayt0mraU36rRu3D3D2SY-QJXOK5XKBk
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:_spf.google.com ip4:218.18.102.9 ip4:184.104.221.16 ip4:202.60.224.209 ip4:45.61.224.184 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:ex_ggly@hepalink.compolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6h+VY4Vx67qgFCrhpjVV4m8PXgaxw0fs3RZiuAD5S1NzbussY/SYxdevCiqcmDIi5n/DuQHIm7WbFz…
selectors probed - selector1:
Certificate (current)
GeoTrust G2 TLS CN RSA4096 SHA256 2022 CA1
Expires in 255 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
ALLOW-FROM https://oat.hepalink.net- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' *.hepalink.com;img-src *;script-src 'self' 'unsafe-inline' cdn.bootcss.com qt.gtimg.cn *.hepalink.com 'unsafe-eval' *.hepalink.com ;frame-ancestors 'self' *.hepalink.net- strict-transport-security
max-age=31536000