shapescan.xyz
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Cloudflare Insights
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×2
- static.cloudflareinsights.com×1
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2024-05-31
- Expires
- 2027-05-31 375 days left
- Updated
- 2026-04-27
- Name servers
-
- yolanda.ns.cloudflare.com
- miles.ns.cloudflare.com
DNS records live
- NS
-
- miles.ns.cloudflare.com
- yolanda.ns.cloudflare.com
- Verified for
-
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;policy: reject (enforced) · sp=reject - DKIM
-
Show 12 DKIM selectors
- default:
v=DKIM1; p= - google:
v=DKIM1; p= - selector1:
v=DKIM1; p= - selector2:
v=DKIM1; p= - k1:
v=DKIM1; p= - k2:
v=DKIM1; p= - mail:
v=DKIM1; p= - dkim:
v=DKIM1; p= - s1:
v=DKIM1; p= - s2:
v=DKIM1; p= - mxvault:
v=DKIM1; p= - smtpapi:
v=DKIM1; p=
selectors probed - default:
Certificate (current)
WE1
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self';connect-src 'self' *.shapescan.xyz shapescan.xyz https://shapescan.xyz https://admin-rs.services.blockscout.com https://contracts-info.services.blockscout.com https://metadata.services.blockscout.com https://user-ops-indexer-shape-mainnet.k8s.blockscout.com https://visualizer.services.blockscout.com wss://shapescan.xyz https://shape-mainnet.g.alchemy.com/public https://infragrid.v.network raw.githubusercontent.com api.github.com coinzilla.com *.coinzilla.com https://request-global.czilladx.com *.adx.ws servedbyadbutler.com *.slise.xyz app.specify.sh *.web3modal.com *.web3modal.org *.walletconnect.com *.walletconnect.org wss://relay.walletconnect.com wss://relay.walletconnect.org wss://www.walletlink.org fonts.gstatic.com https://www.google.com/recaptcha/api2/clr cdn.growthbook.io https://delegated-ipfs.dev https://trustless-gateway.link https://eth.blockscout.com https://explorer.optimism.io https://rootstock.blockscout.com https://etc.blockscout.com https://gnosis.- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin