thaifriendly.com
HTML metadata
Technology
- Server
- PWS
Third-party hosts loaded (1)
- accounts.google.com×1
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2010-01-03
- Expires
- 2028-01-03 593 days left
- Updated
- 2024-09-06
- Name servers
-
- ns-1530.awsdns-63.org
- ns-1781.awsdns-30.co.uk
- ns-348.awsdns-43.com
- ns-966.awsdns-56.net
DNS records live
- NS
-
- ns-1530.awsdns-63.org
- ns-1781.awsdns-30.co.uk
- ns-348.awsdns-43.com
- ns-966.awsdns-56.net
- MX
-
- 10 mxa.mailgun.org
- 10 mxb.mailgun.org
- TXT
-
google-site-verification=Cwq8DaqrCwEvqwZowcErDAtlB-P4Mc79Ac3er2gx7mkgoogle-site-verification=veeD0fS3fHELubqYrCBTO-kLM-PUo0Q3E5SfbmtsQiQ
Email authentication strong
- SPF
-
v=spf1 include:mailgun.org include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;rua=mailto:re+4cb324cd50c8@inbound.dmarcdigests.com;pct=100;policy: reject (enforced) - DKIM
-
- default:
v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7/GFkpI56airA6caOapzEWP/h9xEhp69xrmNds8zf3QQ7JqgxChbHtxy9uAXDZSztjelQyNMHojrRmpdeiVi9Tge7D…
selectors probed - default:
Certificate (current)
R13
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
child-src 'self';connect-src 'self' https://cognito-identity.us-west-2.amazonaws.com https://*.rekognition.amazonaws.com https://cdn.liveness.rekognition.amazonaws.com https://api.openai.com http://*.pinalove.com https://*.googletagmanager.com http://*.thaifriendly.com https://*.apple.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://*.pinalove.com https://*.tenor.com https://*.klipy.com https://*.thaifriendly.com wss: wss://*.pinalove.com wss://*.thaifriendly.com wss://*.vietnameselove.com;default-src 'self';font-src 'self' chrome-extension: data: http://*.gstatic.com https://*.gstatic.com;frame-src 'self' https://*.apple.com https://*.g.doubleclick.net https://*.google.com;img-src 'self' blob: data: http://*.gstatic.com https://*.googletagmanager.com http://*.pinalove.com http://*.thaifriendly.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.at https://*.google.be https://*.google.ca htt- strict-transport-security
max-age=31536000; includeSubDomains; preload