resist.bot
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- JS framework
- Next.js
Third-party hosts loaded (1)
- cdn.sanity.io×4
Social
Registration
- Registrar
- EnCirca, Inc.
- Created
- 2017-11-23
- Expires
- 2026-11-23 166 days left
- Updated
- 2025-10-26
- Name servers
-
- ns1.vercel-dns-2.com
- ns2.vercel-dns-2.com
DNS records live
- NS
-
- ns1.vercel-dns-2.com
- ns2.vercel-dns-2.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; sp=none; rua=mailto:re+ujpzwqw3y7l@inbound.dmarcdigests.com; pct=100policy: quarantine · sp=none - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAow3nxca270Ura9/9+UezWS32Sm7uufJtFvG943+6ZCt9qo2uAH615HNvD+vApfYCj/vyzGPVzm8qA/…
selectors probed - google:
Certificate (current)
R12
Expires in 41 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'none'; child-src 'self' blob:; font-src 'self' data:; frame-ancestors 'none'; object-src 'none'; worker-src 'self' blob:; img-src 'self' blob: data: https://cdn.sanity.io https://d2trsyva2ogxqz.cloudfront.net; script-src 'self' 'unsafe-inline' https://*.posthog.com https://*.js.stripe.com https://js.stripe.com https://maps.googleapis.com https://platform.twitter.com https://sentry.io https://*.sentry.io https://o70939.ingest.sentry.io; style-src 'self' 'unsafe-inline'; connect-src 'self' https://*.posthog.com https://api.stripe.com https://maps.googleapis.com https://api.mapbox.com https://events.mapbox.com https://platform.twitter.com https://sentry.io https://*.sentry.io https://o70939.ingest.sentry.io https://resistbot.report-uri.com https://cdn.sanity.io https://fj76bufg96.execute-api.us-west-2.amazonaws.com https://8qidifgfmb.execute-api.us-west-2.amazonaws.com wss://6w2xcfnz5vh5bckdkcmw6o4d6y.appsync-realtime-api.us-west-2.amazonaws.com https://a.res- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (39)
- wusa9.com×2
- tiktok.com×2
- threads.net×2
- theskimm.com×2
- theguardian.com×2
- teenvogue.com×2
- t.me×2
- stripe.com×2
- snopes.com×2
- salon.com×2
- romper.com×2
- recode.net×2
- oprah.com×2
- nme.com×2
- newsday.com×2
- miamiherald.com×2
- messenger.com×2
- medium.com×2
- lifehacker.com×2
- khou.com×2
- instyle.com×2
- instagram.com×2
- inc.com×2
- huffingtonpost.com×2
- fastcompany.com×2
- engadget.com×2
- democratsabroad.org×2
- democracydocket.com×2
- cottonbureau.com×2
- cbslocal.com×2
- bustle.com×2
- businessinsider.com×2
- bsky.app×2
- bna.com×2
- billboard.com×2
- azcentral.com×2
- apple.com×2
- amendment.app×2
- amazonaws.com×2
Use this data via API
Everything on this page for resist.bot is available as JSON from the indexo.dev REST & MCP API.
curl "https://indexo.dev/api/v1/domains/resist.bot" \ -H "X-API-Key: idx_..."