tokenview.io

.io crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 963 ms crawled 2026-05-18

GB · 8.208.121.51 · AS45102 Alibaba US Technology Co., Ltd.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Tokenview Security Verification
Language
en

Technology

Third-party hosts loaded (1)

  • challenges.cloudflare.com×1

DNS records live

NS
  • ns1cnb.name.com
  • ns2fjz.name.com
  • ns3cna.name.com
  • ns4blx.name.com
MX
  • 10 mx1.titan.email
  • 20 mx2.titan.email
TXT
  • google-site-verification=o6HuRMt3KcLAwExfO8vsR3lSRgggtqblVkdgoKACedU
  • google-site-verification=kjfLj4K_YUD0tRQX4CE0f7VBtmCdgmVejRqQCgsT37w
  • v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdNfYN50t0U0c6ZRt34pESimASdHZje0zJfUTZSF9GDzdYKJugqxu9PAYadkFxBFSIxN29XQGOQJ+Zwo6ghRnJOWtRpWX3DanPuCWM/KTGLN0FhJcm+bit/3sk2d5/FO1RAAPNtvHnCAMrwNmzfIT21TA/NC9t2gBPkSZfxJEwJwIDAQAB

Email authentication weak

SPF
v=spf1 include:spf.titan.email ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-03-10 to 2026-06-08
Expires in 20 days

HTTP security headers

Header hygiene 50/100 Checked live page: https://tokenview.io/challendge.html?redirect=/

present
  • content-security-policy
  • x-frame-options
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: tokenview.io *.tokenview.io pagead2.googlesyndication.com www.googletagmanager.com www.google-analytics.com *.google-analytics.com tpc.googlesyndication.com *.baidu.com *.bdstatic.com dmp.adform.net rtd-tm.everesttech.net cdn.coinzilla.io *.adtrafficquality.google lb.eu-1-id5-sync.com id5-sync.com *.adx.ws coinzillatag.com *.czilladx.com js.hsforms.net recaptcha.net www.gstatic.cn www.gstatic.com cloudinary.com *.cloudinary.com https://cdn.adx.ws/scripts/loader.js https://embed.hel.io createjs.com *.createjs.com adform.net *.adform.net smartadserver.com *.smartadserver.com sascdn.com *.sascdn.com smilewanted.com *.smilewanted.com criteo.com *.criteo.com adnxs.com *.adnxs.com rubiconproject.com *.rubiconproject.com pubmatic.com *.pubmatic.com openx.net *.openx.net sharethrough.com *.sharethrough.com lijit.com *.lijit.com onetag.com *.onetag.com onetag-sys.com *.onetag-sys.com 360yield.com *.360yield.com id5-sync.com *.id5-sync

Linked from (3)