hot168.app
HTML metadata
Technology
- Server
- Apache
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- www.googletagmanager.com×2
- appleid.cdn-apple.com×1
- www.facebook.com×1
Social
Contact
DNS records live
- NS
-
- ns75.domaincontrol.com
- ns76.domaincontrol.com
- MX
-
- 0 hot168-app.mail.eo.outlook.com
- TXT
-
MS=ms70178042facebook-domain-verification=08k3xc1xlq9q96rdo36sy4o7ybiec3
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GoDaddy TLS Intermediate CA DV - R1v1
Expires in 139 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- checked over plain HTTP
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' cdn.hot168.app; font-src 'self' data:; img-src 'self' blob: www.facebook.com cdn.hot168.app i.ytimg.com img.youtube.com data: https://www.google.com https://www.google.com.tw https://www.googletagmanager.com/ https://googleads.g.doubleclick.net https://www.google-analytics.com https://c.clarity.ms/ https://c.bing.com/; script-src 'self' connect.facebook.net appleid.cdn-apple.com www.youtube.com https://websdk.appsflyer.com https://www.googletagmanager.com/ https://www.google-analytics.com/ https://googleads.g.doubleclick.net https://static.hotjar.com www.googleadservices.com http://ajax.googleapis.com/ https://script.hotjar.com https://www.clarity.ms https://www.google.com 'unsafe-inline' https://www.googletagmanager.com/; style-src 'self' 'unsafe-inline'; frame-src 'self' www.youtube.com www.facebook.com https://vars.hotjar.com/ https://www.youtube-nocookie.com/;object-src 'none'; frame-ancestors 'self' www.facebook.com; connect-src 'self' cdn.hot168.app www.faceboo
Links to (6)
- apple.com×1
- facebook.com×1
- gaminglabs.com×1
- google.com×1
- line.me×1
- youtube.com×1