jahir.dev
HTML metadata
Technology
- CDN
- Vercel
Social
Contact
DNS records live
- NS
-
- curitiba.ns.porkbun.com
- fortaleza.ns.porkbun.com
- maceio.ns.porkbun.com
- salvador.ns.porkbun.com
- MX
-
- 10 fwd1.porkbun.com
- 20 fwd2.porkbun.com
- TXT
-
Show 4 TXT records
OSSRH-65258OSSRH-65259OSSRH-65260google-site-verification=HdaUIliWI8l-sG9oM7lkh-1yuHtVlRgBWfGPwCZjZkc
Email authentication strong
- SPF
-
v=spf1 include:amazonses.com include:_spf.porkbun.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:25f8c5e6@mxtoolbox.dmarc-report.com; ruf=mailto:25f8c5e6@forensics.dmarc-report.com; fo=1policy: quarantine - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDgxLm5Q+CVGRYHH37l37Lg7VB8/IlHxUO0c/OyAAkHs2XIiXcTFUji0PjNYPW5wJbwBTFq4ast+1yAqByoRA…
selectors probed - default:
Certificate (current)
R12
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' vercel.live; worker-src 'self' blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.jahir.dev status.lol data:; child-src *.scdn.co *.spotify.com *.jahir.dev unavatar.now.sh *.unavatar.io; style-src 'self' 'unsafe-inline'; img-src * blob: data:; object-src 'none'; base-uri 'none'; media-src 'self' video.twimg.com; connect-src *; font-src 'self' data:;- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (10)
- linkedin.com×6
- bsky.app×4
- github.com×4
- google.com×4
- instagram.com×4
- nwyc.com×4
- threads.com×4
- world-holidays.info×4
- boyaca-dev.org×4
- x.com×4