tokenview.io
HTML metadata
Technology
Third-party hosts loaded (1)
- challenges.cloudflare.com×1
DNS records live
- NS
-
- ns1cnb.name.com
- ns2fjz.name.com
- ns3cna.name.com
- ns4blx.name.com
- MX
-
- 10 mx1.titan.email
- 20 mx2.titan.email
- TXT
-
google-site-verification=o6HuRMt3KcLAwExfO8vsR3lSRgggtqblVkdgoKACedUgoogle-site-verification=kjfLj4K_YUD0tRQX4CE0f7VBtmCdgmVejRqQCgsT37wv=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdNfYN50t0U0c6ZRt34pESimASdHZje0zJfUTZSF9GDzdYKJugqxu9PAYadkFxBFSIxN29XQGOQJ+Zwo6ghRnJOWtRpWX3DanPuCWM/KTGLN0FhJcm+bit/3sk2d5/FO1RAAPNtvHnCAMrwNmzfIT21TA/NC9t2gBPkSZfxJEwJwIDAQAB
Email authentication weak
- SPF
-
v=spf1 include:spf.titan.email ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 20 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: tokenview.io *.tokenview.io pagead2.googlesyndication.com www.googletagmanager.com www.google-analytics.com *.google-analytics.com tpc.googlesyndication.com *.baidu.com *.bdstatic.com dmp.adform.net rtd-tm.everesttech.net cdn.coinzilla.io *.adtrafficquality.google lb.eu-1-id5-sync.com id5-sync.com *.adx.ws coinzillatag.com *.czilladx.com js.hsforms.net recaptcha.net www.gstatic.cn www.gstatic.com cloudinary.com *.cloudinary.com https://cdn.adx.ws/scripts/loader.js https://embed.hel.io createjs.com *.createjs.com adform.net *.adform.net smartadserver.com *.smartadserver.com sascdn.com *.sascdn.com smilewanted.com *.smilewanted.com criteo.com *.criteo.com adnxs.com *.adnxs.com rubiconproject.com *.rubiconproject.com pubmatic.com *.pubmatic.com openx.net *.openx.net sharethrough.com *.sharethrough.com lijit.com *.lijit.com onetag.com *.onetag.com onetag-sys.com *.onetag-sys.com 360yield.com *.360yield.com id5-sync.com *.id5-sync
Linked from (3)
- coincarp.com×4
- navzh.com×3
- bidaka.com×2