sopuli.xyz

.xyz crawl

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 1371 ms crawled 2026-05-19

DE · 138.201.137.130 · AS24940 Hetzner Online GmbH

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Sopuli - A general-purpose instance run by a Finn - everyone is welcome here!
Description
Lemmy
Language
en
Canonical
http://sopuli.xyz/
Feeds

Open Graph

url
http://sopuli.xyz/
title
Sopuli - A general-purpose instance run by a Finn - everyone is welcome here!

Technology

Server
nginx
CMS
Gatsby
Third-party hosts loaded (19)
  • lemmy.world×40
  • mander.xyz×8
  • sh.itjust.works×8
  • lemmy.dbzer0.com×6
  • feddit.org×4
  • lemmy.radio×4
  • reddthat.com×4
  • feddit.uk×2
  • fortune.com×2
  • i.insider.com×2
  • leminal.space×2
  • lemmings.world×2
  • lemmy.ca×2
  • news.mit.edu×2
  • petapixel.com×2
  • quokk.au×2
  • s.yimg.com×2
  • static.independent.co.uk×2
  • www.videogameschronicle.com×2

Social

Registration

Registrar
HOSTINGER operations, UAB
Created
2021-02-01
Expires
2027-02-01 256 days left
Updated
2026-01-11
Name servers
  • ns2.dns-parking.com
  • ns1.dns-parking.com

DNS records live

NS
  • ns1.dns-parking.com
  • ns2.dns-parking.com
MX
  • 10 mx2.hostinger.fi
  • 5 mx1.hostinger.fi
Verified for
  • Brevo

Email authentication partial

SPF
v=spf1 include:spf.titan.email include:spf.mx.hostinger.com include:relay.mailchannels.net include:sopuli.xyz -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com
policy: none (monitoring only)
DKIM
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificate (current)

R12
from 2026-04-17 to 2026-07-16
Expires in 57 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://sopuli.xyz/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self'; manifest-src *; connect-src *; img-src * data: blob:; script-src 'self' 'nonce-1dbc548461c1de019bb7256da0ae43c2'; style-src 'self' 'unsafe-inline'; form-action 'self'; base-uri 'self'; frame-src *; media-src * data:

Links to (30)

Linked from (3)