lushstories.com

.com crawl

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 1111 ms crawled 2026-05-18

US · 104.21.43.50 · AS13335 Cloudflare, Inc.

Reputation 89/100 weak security headers dmarc monitor-only

Classifying

HTML metadata

Title
Lush Stories - Free Sex Stories, Adult Chat and Erotic Stories
Description
Lush sex stories, social network for lovers of erotic stories. Like Facebook but adult, where you can free your spirit and let your sexuality run wild.
Language
en

Technology

CDN
Cloudflare
CMS
Nuxt
Fonts
  • Adobe Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • static.fxxy.net×34
  • use.typekit.net×2
  • fonts.gstatic.com×1

Contact

Phone
Address
st timeanal sexgay maleScore 22189

Registration

Registrar
GoDaddy.com, LLC
Created
2006-09-18
Expires
2026-09-18 122 days left
Updated
2025-09-18
Name servers
  • aaden.ns.cloudflare.com
  • luciana.ns.cloudflare.com

DNS records live

NS
  • aaden.ns.cloudflare.com
  • luciana.ns.cloudflare.com
MX
  • 26 route3.mx.cloudflare.net
  • 28 route1.mx.cloudflare.net
  • 66 route2.mx.cloudflare.net
TXT
Show 4 TXT records
  • wl-verify=60c7c85c45fc50285182
  • ahf7j6so7jnlvkscut6ejgenqf
  • google-site-verification=9aBooEPdD1auK4Y-bm5h5jlzSCtoCFwZXXERDPbyFCc
  • google-site-verification=miK84yO9c5B2NJekyn3tI0Nz4luryEQz7NZMNeD8tiM

Email authentication partial

SPF
v=spf1 include:_spf.mx.cloudflare.net ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:bca4d28e021641969b8b9614f68b236b@dmarc-reports.cloudflare.net
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-04-02 to 2026-07-01
Expires in 43 days

HTTP security headers

Header hygiene 45/100 Checked live page: https://www.lushstories.com/

present
  • content-security-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
base-uri 'none'; object-src 'none'; script-src 'nonce-NFCz4KJOwqXYhRrUeKxO5LnwNqiDAGtFASbi4Kn-uRSkcyU27R3mTTPnDnQ3w1pT' 'strict-dynamic' https: 'unsafe-inline' 'self'

Links to (15)

Linked from (50)