neverhack.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Plausible
Third-party hosts loaded (2)
- plausible.io×3
- www.googletagmanager.com×2
Registration
- Registrar
- OVH sas
- Created
- 2016-04-16
- Expires
- 2027-04-16 331 days left
- Updated
- 2026-04-17
- Name servers
-
- dns200.anycast.me
- ns200.anycast.me
DNS records live
- NS
-
- dns200.anycast.me
- ns200.anycast.me
- MX
-
- 0 neverhack-com.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
google-site-verification=XofkFCBaaMzb7s6cORwX7rh5Dm3sJfoLx3JEoTYzqxAsophos-domain-verification=e2dc56ea032b896c35ecd25a39aabc173d38c7f516abc3e01c36a4c364b39db7apple-domain-verification=tOGEXqdZnaE1TIleMS=ms66760318brevo-code:ab2782f53ba7701540b60bbf0e0710afgoogle-site-verification=H1cH_ViczZutNRUXGJe-WkxfEudtKAMOaMedaoArAD8
Email authentication strong
- SPF
-
v=spf1 ip4:80.79.113.27 ip4:89.90.219.65 ip4:78.202.202.81 ip4:78.199.86.207 ip4:176.175.240.140 ip4:54.228.123.73 ip4:108.142.104.22 ip4:51.178.97.171 include:spf.protection.outlook.com include:mailgun.org -allstrict (-all) - DMARC
-
v=DMARC1;p=quarantine;pct=100;rua=mailto:report@neverhack.com;sp=none;aspf=r;policy: quarantine · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvj+RifaAvY60vdHQzDOsuYOzdjHZp0ekwCTUBcQX2g/VXyaQTrxh7/dzeJrxLGCUrNGcnKQ5ezf+GD…
selectors probed - selector1:
Certificate (current)
E7
Expires in 76 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), microphone=(), geolocation=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' https://js.stripe.com https://maps.googleapis.com https://www.googletagmanager.com https://plausible.io 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; frame-src https://js.stripe.com https://www.googletagmanager.com; connect-src 'self' https://api.stripe.com https://r.stripe.com https://prometheus.neverhack.com https://plausible.io https://www.google-analytics.com https://*.analytics.google.com; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; form-action 'self'- strict-transport-security
max-age=63072000; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups