kroo.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-07 · ok HTTP/1.1 200 366 ms crawled 2026-05-07

US · 13.33.235.45 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Kroo Bank | Home
Description
Who you bank with matters. Kroo Home Page.
Language
en

Open Graph

title
Kroo Bank | Home

Technology

CDN
Amazon CloudFront
CMS
Next.js

Social

Contact

Email

Registration

Registrar
Amazon Registrar, Inc.
Created
1996-08-10
Expires
2026-08-09 80 days left
Updated
2025-07-05
Name servers
  • ns-1513.awsdns-61.org
  • ns-1942.awsdns-50.co.uk
  • ns-250.awsdns-31.com
  • ns-732.awsdns-27.net

DNS records live

NS
  • ns-1513.awsdns-61.org
  • ns-1942.awsdns-50.co.uk
  • ns-250.awsdns-31.com
  • ns-732.awsdns-27.net
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 5 TXT records
  • tresorit-verification=WJ5s3Q6lfogY0-zDbO2I8VtAxtBvQPVN0-n1HLcVFeQ
  • v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQClyCaNq617ze6fF3Z/gndrQE/yb9/qeknMqOg/BYjlIr61AS3CYki99/Xjmp0Zjv250HOZU099lU3DxVjJ8c9zk7z7dme0aOdekfptiVHoHvW71fp1Ga+FEOdpX0vmyCaVqwWTP49s71S/OLVhDRIJmo6QmzEoW5knvyQeceoLJwIDAQAB
  • jamf-site-verification=dmFPyjPnrB0E8ZvSGxhafw
  • mixpanel-domain-verify=ced85767-0c51-49b5-8e2e-27b4fb1f71b0
  • status-page-domain-verification=1snx3d27klb2
Verified for
  • Apple
  • Atlassian
  • Google
  • Meta
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:amazonses.com include:mail.zendesk.com include:revolut.com include:mintago.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc-reports@kroo.com; fo=0; pct=100; adkim=r; aspf=r
policy: reject (enforced)
DKIM
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCIl6lkI3OmhNdyZVlcrqKnbCzZTtci+mMrsaQANtR4ZsXn8SfMWmGGn4s91INh1x9l4/7T/Z6btVBeeZ1cX6…
selectors probed

Certificate (current)

Amazon RSA 2048 M01
from 2026-01-10 to 2027-02-09
Expires in 264 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://kroo.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
same-origin
x-frame-options
deny
permissions-policy
fullscreen=(self "https://*.onfido.com" "https://sdk.onfido.com"), payment=(), sync-xhr=(), geolocation=(self "https://*.onfido.com" "https://sdk.onfido.com"), microphone=(self "https://*.onfido.com" "https://sdk.onfido.com"), camera=(self "https://*.onfido.com" "https://sdk.onfido.com"), magnetometer=(), gyroscope=(), autoplay=(), usb=()
x-content-type-options
nosniff
content-security-policy
connect-src 'self' *.kroo.com rum.browser-intake-datadoghq.eu *.google-analytics.com *.g.doubleclick.net *.analytics.google.com *.trustpilot.com *.googletagmanager.com us-central1-adaptive-growth.cloudfunctions.net/pdst-events-prod-sink pagead2.googlesyndication.com *.hotjar.io wss://ws.hotjar.com *.google.com *.onfido.com sdk.onfido.com wss://sync.onfido.com solve-widget.forethought.ai/embed.js.map web-api.kroo.com; default-src 'self'; font-src 'self' https://fonts.googleapis.com/css https://fonts.gstatic.com; frame-src solve-widget.forethought.ai/ *.trustpilot.com td.doubleclick.net player.vimeo.com *.googletagmanager.com *.onfido.com *.youtube.com; img-src 'self' https: data:; object-src 'none'; script-src-elem 'self' 'unsafe-inline' solve-widget.forethought.ai/embed.js *.trustpilot.com *.googletagmanager.com *.hotjar.com connect.facebook.net cdn.pdst.fm/ping.min.js *.google-analytics.com/analytics.js *.googleoptimize.com/optimize.js googleads.g.doubleclick.net *.googleadservices.
strict-transport-security
max-age=31104000; includeSubDomains; preload

Links to (6)

Linked from (1)