neohotels.com

.com crawl

First seen 2026-05-30 · Last seen 2026-05-31 · ok HTTP/1.1 200 1035 ms crawled 2026-05-31

US · 18.165.140.125 · AS16509 Amazon.com, Inc.

Reputation 86/100 dmarc partial coverage weak subdomain policy

Classifying

Technology

CDN
Amazon CloudFront
Server
CloudFront

Registration

Registrar
Gandi SAS
Created
2004-06-28
Expires
2027-06-28 391 days left
Updated
2026-05-24
Name servers
  • ns-1480.awsdns-57.org
  • ns-1575.awsdns-04.co.uk
  • ns-226.awsdns-28.com
  • ns-884.awsdns-46.net

DNS records live

NS
  • ns-1480.awsdns-57.org
  • ns-1575.awsdns-04.co.uk
  • ns-226.awsdns-28.com
  • ns-884.awsdns-46.net
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com

Email authentication partial

SPF
v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net -all
strict (-all)
DMARC
v=DMARC1; p=reject; sp=none; rua=mailto:sentec-d@dmarc.report-uri.com; ruf=mailto:sentec-d@dmarc.report-uri.com; rf=afrf; pct=99; ri=86400
policy: reject (enforced) · pct=99 · sp=none
DKIM
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDS3FfwdCQGPJ81TbGNh+bTCqPDA++UFa5nm9y06MKCbc624jrcARAcUMPqAEPmBM7t/aAqiEBebjr5NVt0v3…
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

Amazon RSA 2048 M04
from 2025-10-31 to 2026-11-30
Expires in 181 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://neohotels.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
geolocation=(self "https://www.google-analytics.com"), camera=(), fullscreen=(self), microphone=()
x-content-type-options
nosniff
content-security-policy
frame-ancestors 'self' *.ampproject.org; block-all-mixed-content; default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' data: https://challenges.cloudflare.com *.archipelagointernational.com static.neohotels.com translate.googleapis.com translate.google.com www.youtube.com m.youtube.com www.googletagmanager.com googletagmanager.com tagmanager.google.com *.affilired.com *.denomatic.com *.glopss.com embed.tawk.to cdn.jsdelivr.net connect.facebook.net graph.facebook.com js.facebook.com www.google-analytics.com ssl.google-analytics.com google-analytics.com cdnjs.cloudflare.com cdn0.neohotels.com *.triptease.io onesignal.com cdn.onesignal.com *.doubleclick.net *.googleadservices.com *.google.com *.googlesyndication.com *.googletagservices.com cdn.ampproject.org www.recaptcha.net recaptcha.net www.gstatic.com www.gstatic.cn www.google.com; style-src 'self' 'report-sample' 'unsafe-inline' https://*.archipelagointernational.com translate.googleapis.com www.googlet
strict-transport-security
max-age=31536000; includeSubdomains

Linked from (2)