topograph.app

.app crawl

First seen 2026-06-03 · Last seen 2026-06-03 · ok HTTP/1.1 200 301 ms crawled 2026-06-04

US · 104.21.48.100 · AS13335 Cloudflare, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
topograph - Topographic maps from elevation data
Description
Create topographic contour maps from real elevation data or procedural terrain. Preview in 3D with 20 shader styles. Export SVG, PNG, TIFF, PDF, DXF, GeoJSON, Heightmap, STL up to 600 DPI.
Language
en
Canonical
https://topograph.app/

Open Graph

url
https://topograph.app/
title
topograph - Topographic maps from elevation data
locale
en_US
site name
topograph
description
Topographic maps from elevation data. Real or procedural terrain.

Technology

CDN
Cloudflare
Analytics
  • Cloudflare Insights
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • cdn.jsdelivr.net×2
  • fonts.googleapis.com×2
  • fonts.gstatic.com×1
  • static.cloudflareinsights.com×1

DNS records live

NS
  • cleo.ns.cloudflare.com
  • marlowe.ns.cloudflare.com
MX
  • 10 mx01.mail.icloud.com
  • 10 mx02.mail.icloud.com
TXT
  • apple-domain=ayTlbtdFscI9eZ9y
  • apple-domain=g9MaefQC3APnfxrC

Email authentication weak

SPF
v=spf1 include:icloud.com include:_spf.mx.cloudflare.net ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-05-08 to 2026-08-06
Expires in 61 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://topograph.app/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(self), microphone=(), camera=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://api.topograph.app https://cdn.jsdelivr.net https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob: https:; connect-src 'self' https://api.topograph.app https://staging-api.topograph.app http://localhost:8787 https://nominatim.openstreetmap.org https://cdn.jsdelivr.net; frame-src 'self' https://*.stripe.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self';
strict-transport-security
max-age=31536000; includeSubDomains; preload

Linked from (1)