tiffathai.org
HTML metadata
Technology
- Server
- nginx
- PHP
- 8.2.31 security-only
- jQuery
- 2.2.4 known XSS (<3.5)
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- cdnjs.cloudflare.com×2
- code.jquery.com×2
- fonts.googleapis.com×1
- maxcdn.bootstrapcdn.com×1
Contact
- Phone
DNS records live
- NS
-
- maya.ns.cloudflare.com
- paul.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- Verified for
-
- GlobalSign
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 +a +mx +ip4:119.59.126.33 include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzAeBekmeH2V3wkgcvPMEoawhWcrTld9i+Oj5RHRx5r9Yil71c+rtXEXKH2oYSAC29Serln99/XsJxb… - google:
v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4TtkpJcjubp5hCGz3GEQZ97S4Eg7GHnwQ3uU93tpaIrA+P5qh8ko4BopjUAo4YdZ2J6XuwmqnlNUJlwl…
selectors probed - default:
Certificate (current)
GlobalSign GCC R6 AlphaSSL CA 2025
Expires in 63 days
HTTP security headers
- findings
-
- missing HSTS
- missing Content Security Policy
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Links to (6)
- youtube.com×1
- tafathai.org×1
- messenger.com×1
- line.me×1
- instagram.com×1
- facebook.com×1
tiffathai.org