stopncii.org

.org crawl

First seen 2026-04-13 · Last seen 2026-05-08 · ok HTTP/1.1 200 420 ms crawled 2026-05-06

GB · 87.106.96.56 · AS8560 IONOS SE

Reputation 97/100 dmarc monitor-only

Classifying

HTML metadata

Title
Stop Non-Consensual Intimate Image Abuse | StopNCII.org
Description
StopNCII.org is operated by the Revenge Porn Helpline which is part of SWGfL, a charity that believes that all should benefit from technology, free from harm.
Language
en-gb

Technology

Server
nginx

Registration

Registrar
NameCheap, Inc.
Created
2021-08-11
Expires
2026-08-11 84 days left
Updated
2026-01-26
Name servers
  • dns1.registrar-servers.com
  • dns2.registrar-servers.com

DNS records live

NS
  • dns1.registrar-servers.com
  • dns2.registrar-servers.com
MX
  • 0 stopncii-org.mail.protection.outlook.com
TXT
  • MS=ms13488905
  • v:spf1 a mx include:spf.protection.outlook.com -all
  • google-site-verification=EbjCWAljCihjbsIKa2xvvfiKTHg0NyhFOkfnTe5CWXw

Email authentication partial

SPF
not published
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • default: v=DKIM1; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzS1ic++tQNOZwXFoPYZTRFZIbD4NUQU0Z/9ZgQ0ms5yc+98TSkPtsROVy0p8Wm8VcHOYqi0I/GWxJRa7Ywb5i…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyeW6cYyB7f5n/n+EQZy0Z7ZWaDX/80OajwikVFok4IdnY2bUHtr8U5N2dvFZn08nYS7heoccsfv7bGMJZC…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuxzXpHR2FcWZDPRpOhV6Q4AIbgrVAysTBbbatVf2WPRkklIzC6vdnJ9czJ7k9xw//0Pk7qjzyTdT4dyU2G…
selectors probed

Certificate (current)

R13
from 2026-04-10 to 2026-07-09
Expires in 51 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://stopncii.org/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), autoplay=(self), camera=(), display-capture=(), fullscreen=(self), geolocation=(), microphone=(), web-share=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://*.google.com https://www.googletagmanager.com; img-src 'self' data: https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.uk https://*.gstatic.com https://maps.googleapis.com blob:; script-src 'self' https://*.googletagmanager.com https://www.gstatic.com https://*.google.com https://*.google-analytics.com https://*.google.co.uk https://*.g.doubleclick.net https://maps.googleapis.com https://www.googleadservices.com 'wasm-unsafe-eval'; worker-src 'self' blob:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.uk https://maps.googleapis.com; object-src 'none'; frame-ancestors 'self' https://www.go
strict-transport-security
max-age=63072000; includeSubDomains
cross-origin-opener-policy
same-origin

Links to (1)

Linked from (2)