sysleaks.com

.com crawl

First seen 2026-04-20 · Last seen 2026-05-11 · ok HTTP/1.1 200 1963 ms crawled 2026-05-14

DE · 49.13.46.13 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
SysLeaks
Description
"SysLeaks significantly reduces our attack surface by helping us to react to publicly leaked passwords promptly." - CISO Vienna University of Economics and Business. Are there leaked passwords for your domain? How many of your passwords were leaked recently? What is your domain's latest password leak?
Language
en

Technology

CMS
Nuxt

Registration

Registrar
Hetzner Online GmbH
Created
2023-12-15
Expires
2026-12-15 209 days left
Updated
2025-12-16
Name servers
  • helium.ns.hetzner.de
  • hydrogen.ns.hetzner.com
  • oxygen.ns.hetzner.com

DNS records live

NS
  • helium.ns.hetzner.de
  • hydrogen.ns.hetzner.com
  • oxygen.ns.hetzner.com
MX
  • 0 sysleaks-com.mail.protection.outlook.com
TXT
  • google-site-verification=2ikmmFdIBhnPUDu_xS-MAo0FRRZUIQfK26PtGnyUJXs
  • have-i-been-pwned-verification=dweb_cq4344yrmof18kvtp5zd99ce
  • MS=ms54890686

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
not published
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0lWwK0J00FGu1vzTOs8AhM47a7JiSee0Wdh2b62aNJO1fqYk1YwADyTNKxDLcC0o8ZGaQhlHGwDoiY…
selectors probed

Certificate (current)

R12
from 2026-04-18 to 2026-07-17
Expires in 59 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://sysleaks.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
same-origin
x-frame-options
DENY
permissions-policy
publickey-credentials-get=(self), clipboard-write=(self), accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), gamepad=(), speaker-selection=()
x-content-type-options
nosniff
content-security-policy
default-src 'none'; img-src 'self' data:; font-src 'self'; worker-src 'self'; connect-src 'self'; frame-src https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; form-action 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'nonce-MAJ8jwiG2nRLh8iMQW4Ejg' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin

Linked from (1)