mintboys.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Analytics
Third-party hosts loaded (2)
- adultsearch.com×1
- www.google-analytics.com×1
Social
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2015-05-23
- Expires
- 2033-05-23 2560 days left
- Updated
- 2023-08-25
- Name servers
-
- kami.ns.cloudflare.com
- toby.ns.cloudflare.com
DNS records live
- NS
-
- kami.ns.cloudflare.com
- toby.ns.cloudflare.com
- MX
-
- 10 in1-smtp.messagingengine.com
- 20 in2-smtp.messagingengine.com
- TXT
-
google-site-verification=m0eXoMFlilAc_d5wgr1kjzgC0IHZ89NjDVMYu7SoW5E
Email authentication weak
- SPF
-
v=spf1 include:spf.messagingengine.com include:sendgrid.net a:hmail.jitbit.com ?allneutral (?all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1VdYXe3q/kOD4Uzv3rxtZuq1aEwSgJoQZbTvxofPx/G+CuustuGdA5HuMTz380j/4lNLg1KwQNiJ0laAZu… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCk0+WSavZuBcGqHw5ljL5kb4EpVQ4oODwETU0od2hdm+8A17WD661y5k/IYzB529/8BmJ6+LFlIojv1DULxk8pXs…
selectors probed - s1:
Certificate (current)
E8
Expires in 56 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-eval' data: blob: https://stats.g.doubleclick.net https://ampcid.google.ru https://api2.amplitude.com https://cdn.amplitude.com https://hot.com https://adultsearch.com https://www.mintboys.com https://cdn.mintboys.net https://cdn.mintboys.com https://assets.mintboys.com https://cdn.ampproject.org https://amp-error-reporting.appspot.com https://ampcid.google.com https://ampcid.google.com.mx https://ampcid.google.co.uk https://ampcid.google.com.au https://ampcid.google.ca https://ampcid.google.ae https://www.googletagmanager.com https://www.google-analytics.com https://*.ptawe.com/ https://*.awempire.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: login:49 Refused to load the script https://cdn.heapanalytics.com https://cdn.amplitude.com https://unpkg.com https://www.mintboys.com https://hot.com https://cdn.mintboys.net https://cdn.mintboys.com https://assets.mintboys.com https://www.google-analytics.com https://adultsearch.com https://www.googletagm- strict-transport-security
max-age=15552000; includeSubDomains; preload
Links to (4)
- twitter.com×4
- instagram.com×4
- snapchat.com×4
- hot.com×4