loyalfans.com

.com crawl

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 1493 ms crawled 2026-05-18

US · 54.156.128.14 · AS14618 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
LoyalFans.com
Description
LoyalFans seamlessly connects all types of artists, entertainers, musicians, writers, and influencers to their fans and friends. Fans can follow, subscribe, or pay-per-item to get access to the latest photos, videos, audio recordings, and blog posts giving you a new way to connect with who and what's important to you.
Language
en

Open Graph

url
https://www.loyalfans.com
title
Welcome to LoyalFans.com
site name
loyalfans.com
description
LoyalFans seamlessly connects all types of artists, entertainers, musicians, writers, and influencers to their fans and friends. Fans can follow, subscribe, or pay-per-item to get access to the latest photos, videos, audio recordings, and blog posts giving you a new way to connect with who and what's important to you.

Technology

Server
nginx
CMS
Gatsby
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.gstatic.com×3
  • api.lovense-api.com×1
  • www.googletagmanager.com×1

Registration

Registrar
Moniker Online Services LLC
Created
2004-09-15
Expires
2031-09-15 1944 days left
Updated
2025-11-24
Name servers
  • ns-1364.awsdns-42.org
  • ns-1895.awsdns-44.co.uk
  • ns-227.awsdns-28.com
  • ns-857.awsdns-43.net

DNS records live

NS
  • ns-1364.awsdns-42.org
  • ns-1895.awsdns-44.co.uk
  • ns-227.awsdns-28.com
  • ns-857.awsdns-43.net
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 4 TXT records
  • google-site-verification=ABfF9goOokgr2elnr3tQeoKstNhZJFQPNr_rzDrW1g4
  • google-site-verification=NDuSorE628wxukpWHvVCfWWZBEoXR84F_so0JZNSyFU
  • google-site-verification=PIYMx_ASGeSlHEGbFHv5zT0dpadn6clQ_DNDtWKJD9M
  • ivhbqr2u1d950350082rd0ucrc

Email authentication strong

SPF
v=spf1 +a +mx +ip4:149.72.236.42 +ip4:149.72.173.229 +ip4:159.183.133.86 +ip4:149.72.92.35 include:_spf.google.com include:sendgrid.net include:mail.zendesk.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject
policy: reject (enforced)
DKIM
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCe9/ygHhbqGWvDA2ekW1BOh37JLWYhY7gG0Je5wqIjUJpA1D4Mlq98XwBm7hhTFYs06uvB4HKeXc1dJOeIwq…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4sinLZX09I0weh7pG64ab0SDmfWRXOke+j7m1bPKWu2x2nhBu4o7jE3hEXMXV5Ov3X0stC2/agTtA2bBFH…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5YvO7jHn12paz6VSAUtZEJM59frLrqNii5IZxE9Dcf2fGUBuq3ivSvgGHCE2ruXQIEHIQla8erGaW2P2xIvqbKg…
selectors probed

Certificate (current)

Amazon RSA 2048 M04
from 2026-02-04 to 2027-03-05
Expires in 289 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.loyalfans.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' *.loyalfans.com blob:; media-src 'self' *.loyalfans.com blob: data: endsun-s3adt-vu.s3.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.loyalfans.com https://*.google-analytics.com https://*.googletagmanager.com https://pay.wnu.com https://*.cloudflare.com https://cdnjs.cloudflare.com/ajax/libs/quill/ https://translate.google.com https://*.googleapis.com https://*.google.com https://*.gstatic.com https://*.hotjar.com wss://*.hotjar.com https://*.doubleclick.net https://fpnpmcdn.net https://*.lovense-api.com; img-src 'self' https: data: blob:; style-src 'self' 'unsafe-inline' *.loyalfans.com https://*.googleapis.com https://*.gstatic.com https://unpkg.com; font-src 'self' data: *.loyalfans.com https://*.googleapis.com https://*.gstatic.com https://unpkg.com; frame-src 'self' https://*.youtube.com https://*.googletagmanager.com https://*.cardinalcommerce.com https://*.google.com https://*.triple-a.io https://*.doubleclick.net; object-src 'none'; b
strict-transport-security
max-age=31536000; includeSubDomains; preload

Linked from (50)