kcex.io
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- openresty
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- www.kcex.com×33
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns-1096.awsdns-09.org
- ns-1551.awsdns-01.co.uk
- ns-359.awsdns-44.com
- ns-651.awsdns-17.net
- TXT
-
google-site-verification=XpSlPBmfkVq9KOVHIb929TMPQb4YZOVZYOXJIJN6M4gwp-domain-ownership-verification.blog.kcex.io=1e204714d7cda2d62bc0384fb5b092e473c0ff6feb78df905de25e5433367117
Email authentication no MX
- SPF
- not published
- DMARC
-
v=DMARC1; p= quarantine; rua=mailto:dmarc@kcex.io; sp=quarantinepolicy: quarantine · sp=quarantine - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M04
Expires in 154 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.picdenlab.com https://*.kcex.io https://*.kcex.vip https://*.kcex.com https://*.mixdesk.net https://*.instant-chats.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: https://*.picdenlab.com https://mediaconvertly.com https://shop-cart.app https://trkwwtarget.com https://performadspartners.com https://rtgio.co https://*.rtgio.co https://trackadshub.com https://*.kcex.io https://*.kcex.vip https://*.kcex.com https://*.instant-chats.com https://*.twitter.com https://clicks2.com https://*.awswaf.com https://*.bing.com https://*.clarity.ms https://*.dsspn.com https://*.gstatic.com https://*.geetest.com https://*.geevisit.com https://*.qbox.me https://*.cdn-apple.com https://*.mixdesk.com https://*.mixdesk.net https://*.mediamathrdrt.com https://*.google-analytics.com https://*.googletagmanager.com https://*.google.com https://*.jsdelivr.net; style-src 'self' https: 'unsafe-inline' https://*.google.com; img-src 'self' https: blob: data:; font-src '- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (4)
- t.me×2
- kcex.com×1
- apple.com×1
- google.com×1
Linked from (1)
- kcex.com×2