traveloka.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- CMS
- Next.js
Third-party hosts loaded (4)
- ik.imagekit.io×93
- d1785e74lyxkqq.cloudfront.net×38
- cdnjs.cloudflare.com×3
- d9253bf4bdfd.edge.sdk.awswaf.com×3
Social
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2011-01-23
- Expires
- 2027-01-23 248 days left
- Updated
- 2026-05-15
- Name servers
-
- ns-1047.awsdns-02.org
- ns-1823.awsdns-35.co.uk
- ns-205.awsdns-25.com
- ns-616.awsdns-13.net
DNS records live
- NS
-
- ns-1047.awsdns-02.org
- ns-1823.awsdns-35.co.uk
- ns-205.awsdns-25.com
- ns-616.awsdns-13.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 18 TXT records
teamviewer-sso-verification=78b24bb632274ed7b082b44c9c165722v=verifydomain MS=1159920284f93db-54c6-4439-a54d-38291fc3309c49YWE2R3_s-YMZoZLI6vCRbJMS=ms18160568"google-site-verification=roEtuvOVpHdFTP1gUN7eTfuWZAzXKolku1O7OPqhfuQ"anthropic-domain-verification-daxbbd=cWyLqU67wVAlBxeCNFjyb2hTaapple-domain-verification=8JqznNff7f4V45Liatlassian-domain-verification=Ex6Q7vt8BNJ2NUb99TPzLrd1ETWB3ZSxuGVSTVaiYaWI+g8nW52uLZS6ccr4grQ1facebook-domain-verification=hs4c0mdjhgs9hi6tqghk3qzug0nn9tgoogle-site-verification=IHLtgGILsDzHHl4mGIL2A3lNz0Fz6G3jlJJRyptH1togoogle-site-verification=Ox4_p9CD5AF-kZ-ekNAtVI80eTLsImBcFV0DvOEZftEgoogle-site-verification=XagycXfdXojI1cH25WNLApFPBbxubySxEqJv2WAFckAgoogle-site-verification=khF1A9Hxrq1seuPS-Gsl7dTFUrQk25QrrLwl7DsVflYgoogle-site-verification=n6tb9v3Sh5jCqD3NuZBmVIZdekLEs6QgVtscVj2x3Vkgoogle-site-verification=roEtuvOVpHdFTP1gUN7eTfuWZAzXKolku1O7OPqhfuQgoogle-site-verification=wgpvpsCVu-mbIiikrQZk0TgTsRhJ5xI4EJRDlM5kMNQmiro-verification=2cd92f61eebbee1f31c5c99c5aefcbfc48746def
Email authentication strong
- SPF
-
v=spf1 include:_spf.createsend.com include:sendgrid.net include:_spf.google.com include:amazonses.com include:ncapp02.com include:_spf.salesforce.com include:mail.zendesk.com include:45527cfe.ppspf.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc@traveloka.com; pct=100; adkim=r; aspf=rpolicy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo9cdLlGCYUBEjM7V31NF+3kfCPeceiJxtG8+sF3tW/XecaYlN9OKNVcuQX9GXR1H8LVyusU6g98yss… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M04
Expires in 224 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
microphone=()- x-content-type-options
nosniff- content-security-policy
report-uri https://tvlk.report-uri.com/r/d/csp/enforce, upgrade-insecure-requests; frame-ancestors 'self' https://*.traveloka.com- strict-transport-security
max-age=63072000; includeSubDomains; preload- content-security-policy-report-only
script-src 'unsafe-inline' 'unsafe-eval' https: blob:; object-src data: https://d1785e74lyxkqq.cloudfront.net https://h.online-metrix.net; base-uri 'none'; report-uri https://tvlk.report-uri.com/r/d/csp/reportOnly