netaffinity.io

.io crawl

First seen 2026-05-27 · Last seen 2026-05-31 · ok HTTP/1.1 200 1665 ms crawled 2026-05-30

IE · 52.212.132.85 · AS16509 Amazon.com, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Net Affinity App
Language
en

Technology

Server
Apache

Third-party hosts loaded (1)

  • kit.fontawesome.com×1

DNS records live

NS
  • ns-1391.awsdns-45.org
  • ns-1582.awsdns-05.co.uk
  • ns-286.awsdns-35.com
  • ns-968.awsdns-57.net
MX
  • 10 mail.hotels.netaffinity.net
Verified for
  • Google

Email authentication partial

SPF
v=spf1 mx include:netaffinity.net -all
strict (-all)
DMARC
v=DMARC1;p=none;sp=none;pct=100;rua=mailto:spamadmin@netaffinity.io;ruf=mailto:spamadmin@netaffinity.io
policy: none (monitoring only) · sp=none
DKIM
  • default: v=DKIM1; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC2rZjQXw6TMWGcwabmdS3eBvqzYdiTRJG5xqqOyI6z0L4LhYrUo681XUu9kQCZDQQ6yym9YfJbIXbU35WTVxsG…
selectors probed

Certificate (current)

R13
from 2026-04-04 to 2026-07-03
Expires in 32 days

HTTP security headers

Header hygiene 60/100 Checked live page: https://app.netaffinity.io/

present
  • strict-transport-security
  • content-security-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
frame-src 'self' 'unsafe-inline' 'unsafe-eval' * blob: data: * ; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: app.netaffinity.io app.office.netaffinity.net app.demo.netaffinity.net app.uat.netaffinity.net *.ecodev.netaffinity.net *.staging.ecodev.netaffinity.net *.host.staging.ecodev.netaffinity.net *.adyen.com bat.bing.com maxcdn.bootstrapcdn.com checkoutshopper-test.adyen.com checkoutshopper-live.adyen.com cdnjs.cloudflare.com cdn-a.cumul.io app.cumul.io pay.sandbox.datatrans.com pay.datatrans.com www.facebook.com connect.facebook.net forms.hsforms.com heapanalytics.com cdn.heapanalytics.com js.hsforms.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js-eu1.hs-scripts.com js.hsleadflows.net js-eu1.hs-analytics.net js-eu1.hscollectedforms.net forms-eu1.hscollectedforms.net forms-eu1.hsforms.com js-eu1.hs-banner.com api.hubspot.com api-eu1.hubspot.com app.hubspot.com track.hubspot.com track-eu1.hubspot.com forms.hubspot.com js.hubspotfeedback.com pay.google.co
strict-transport-security
max-age=31536000; includeSubDomains; preload;

Linked from (2)