timetoloot.com

.com crawl

First seen 2026-05-14 · Last seen 2026-05-19 · ok HTTP/1.1 200 10118 ms crawled 2026-05-19

SG · 35.213.189.31 · AS15169 Google LLC

Reputation 89/100 weak security headers dmarc monitor-only

Classifying

HTML metadata

Title
Time to Loot – Finding fun in loot and adventure
Description
Finding fun in loot and adventure
Language
en-NZ
Generator
WordPress 6.9.4
Canonical
https://www.timetoloot.com/
Feeds

Open Graph

url
https://www.timetoloot.com/
title
Time to Loot
locale
en_US
site name
Time to Loot
description
Finding fun in loot and adventure

Technology

Server
nginx
CMS
WordPress
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts
Third-party hosts loaded (14)
  • fonts.googleapis.com×2
  • stats.wp.com×2
  • www.goodreads.com×2
  • www.googletagmanager.com×2
  • 0.gravatar.com×1
  • 1.gravatar.com×1
  • 2.gravatar.com×1
  • fonts.gstatic.com×1
  • gmpg.org×1
  • i.gr-assets.com×1
  • images.gr-assets.com×1
  • s0.wp.com×1
  • s1.feedly.com×1
  • widgets.wp.com×1

Social

Contact

Phone

Registration

Registrar
Tucows Domains Inc.
Created
2019-01-20
Expires
2027-01-20 245 days left
Updated
2026-01-02
Name servers
  • ns1.siteground.net
  • ns2.siteground.net

DNS records live

NS
  • ns1.siteground.net
  • ns2.siteground.net
MX
  • 10 mx10.antispam.mailspamprotection.com
  • 20 mx20.antispam.mailspamprotection.com
  • 30 mx30.antispam.mailspamprotection.com

Email authentication partial

SPF
v=spf1 +a +mx +a:sgp48.siteground.asia include:timetoloot.com.spf.auto.dnssmarthost.net ~all
softfail (~all)
DMARC
v=DMARC1; p=none; aspf=r; adkim=r;
policy: none (monitoring only)
DKIM
  • default: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8ErTpKM70Rc0uC704/nV10fIUvFvu8bcotcz3900KGJMseUwVm+JM+bGpFo3FXN1JYCv55El0IkgQS…
selectors probed

Certificate (current)

R12
from 2026-05-13 to 2026-08-11
Expires in 83 days

HTTP security headers

Header hygiene 35/100 Checked live page: https://www.timetoloot.com/

present
  • permissions-policy
findings
  • missing HSTS
  • missing Content Security Policy
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
Header values
permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")

Links to (18)

Linked from (2)