jfkairport.com

.com crawl

First seen 2026-04-17 · Last seen 2026-05-20 · ok HTTP/1.1 200 2208 ms crawled 2026-05-12

US · 104.18.22.236 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
John F. Kennedy International Airport - JFK Airport
Description
Welcome to JFK Airport, New York’s international gateway. Find flight info, maps, transportation, parking, and traveler tips all in one place.
Language
en-us
Canonical
https://www.jfkairport.com/

Open Graph

url
https://www.jfkairport.com/
title
John F. Kennedy International Airport - JFK Airport
description
Welcome to JFK Airport, New York’s international gateway. Find flight info, maps, transportation, parking, and traveler tips all in one place.

Technology

CDN
Cloudflare
CMS
Next.js

Third-party hosts loaded (1)

  • assets.adobedtm.com×1

Registration

Registrar
CSC Corporate Domains, Inc.
Created
1996-04-01
Expires
2027-04-02 316 days left
Updated
2026-03-29
Name servers
  • eve.ns.cloudflare.com
  • langston.ns.cloudflare.com

DNS records live

NS
  • eve.ns.cloudflare.com
  • langston.ns.cloudflare.com
Verified for
  • Google
  • Meta

Email authentication no MX

SPF
not published
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

E8
from 2026-05-03 to 2026-08-01
Expires in 72 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://www.jfkairport.com/

present
  • strict-transport-security
  • content-security-policy
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(), microphone=(), camera=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval'; base-uri 'self'; object-src 'none'; frame-ancestors 'self';
strict-transport-security
max-age=31536000; includeSubDomains; preload
content-security-policy-report-only
default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval'; base-uri 'self'; object-src 'none'; frame-ancestors 'self';

Linked from (2)