thuthuatchoi.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (1)
- static.cloudflareinsights.com×1
Social
Registration
- Registrar
- Name.com, Inc.
- Created
- 2019-07-25
- Expires
- 2028-07-25 797 days left
- Updated
- 2025-07-04
- Name servers
-
- derek.ns.cloudflare.com
- naomi.ns.cloudflare.com
DNS records live
- NS
-
- derek.ns.cloudflare.com
- naomi.ns.cloudflare.com
- MX
-
- 10 mx.zoho.com
- 20 mx2.zoho.com
- 50 mx3.zoho.com
- TXT
-
Show 4 TXT records
zoho-verification=zb34328892.zmverify.zoho.comgoogle-site-verification=0Sn_UKh7e0irLeGiaf1h0S6Ax4xQcKcy0Gi1wLf794Ygoogle-site-verification=BzyLuII2Y0FboPcWYaCLH2fKbAQA8lr5eClPxRHI_w0google-site-verification=Fk6tKArBkOabHOcmmalnK0j_0X1tQxz56MKkltxS95A
Email authentication weak
- SPF
-
v=spf1 include:zoho.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 45 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.zappingchat.com *.thuthuatchoi.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' tzegilo.com al5sm.com *.zappingchat.com *.googletagmanager.com *.cloudflareinsights.com *.googlesyndication.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.gstatic.com *.google.com *.adtrafficquality.google; style-src 'self' 'unsafe-inline' *.googleapis.com *.google.com; img-src 'self' data: *.googletagmanager.com *.thuthuatchoi.com *.zappingchat.com *.fbcdn.net *.facebook.com *.google-analytics.com *.googlesyndication.com *.googleusercontent.com *.gstatic.com *.google.com *.adtrafficquality.google *.google.com.vn; frame-src 'self' *.google.com *.doubleclick.net *.googlesyndication.com *.adtrafficquality.google *.google.com *.zappingchat.com; fenced-frame-src 'self' *.google.com *.doubleclick.net *.googlesyndication.com *.adtrafficquality.google *.google.com; font-src 'self' *.gstatic.com; connect-src 'self' *.zappingchat.com *.google-analytics.com *.adtraff- strict-transport-security
max-age=31536000; includeSubDomains; preload