toph.co

.co crawl

First seen 2026-04-12 · Last seen 2026-05-19 · ok HTTP/1.1 200 1602 ms crawled 2026-05-06

SG · 172.104.40.125 · AS63949 Akamai Connected Cloud

Reputation 100/100

Classifying

HTML metadata

Title
Toph - Competitive Programming Platform
Description
Participate in exhilarating programming contests, solve unique algorithm and data structure challenges and be a part of an awesome community.
Language
en
Canonical
https://toph.co/

Open Graph

url
https://toph.co/
title
Toph - Competitive Programming Platform
description
Participate in exhilarating programming contests, solve unique algorithm and data structure challenges and be a part of an awesome community.

Social

Contact

Address
st a contestAcademic programHandbookPricing© 2026

DNS records live

NS
  • ns1.linode.com
  • ns2.linode.com
  • ns3.linode.com
  • ns4.linode.com
  • ns5.linode.com
MX
  • 10 in1-smtp.messagingengine.com
  • 20 in2-smtp.messagingengine.com
Verified for
  • Google
  • Meta

Email authentication strong

SPF
v=spf1 a mx include:spf.mtasv.net include:spf.messagingengine.com include:servers.mcsv.net include:amazonses.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@toph.co,mailto:re+wcjk3uubump@dmarc.postmarkapp.com; sp=quarantine; aspf=r;
policy: quarantine · sp=quarantine
DKIM
no key found at common selectors

Certificate (current)

E8
from 2026-05-04 to 2026-08-02
Expires in 73 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://toph.co/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
sameorigin
x-content-type-options
nosniff
content-security-policy
default-src 'self' *.toph.co 'unsafe-eval' 'unsafe-inline'; img-src * data:; font-src * data:; connect-src 'self' wss: ws.toph.co static.toph.co uploads.toph.co o28885.ingest.sentry.io; script-src 'self' *.toph.co 'unsafe-eval' 'unsafe-inline' hcaptcha.com *.hcaptcha.com; frame-src 'self' *.toph.co hcaptcha.com *.hcaptcha.com; style-src 'self' *.toph.co 'unsafe-inline' hcaptcha.com *.hcaptcha.com; frame-ancestors 'self' *.toph.co;
strict-transport-security
max-age=63072000; includeSubDomains; preload
cross-origin-opener-policy
same-origin

Links to (6)

Linked from (2)