xeve.ai

.ai crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 950 ms crawled 2026-05-18

US · 199.36.158.100 · AS54113 Fastly, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
xeve.ai - Free AI Girlfriends, AI Striptease & AI Sexting
Description
Chat and video with ultra-realistic AI girlfriends. Interactive AI sexting and companionship in one place. AI Girlfriends, AI Video Chat, AI Striptease & AI Sexting
Language
en
Canonical
https://xeve.ai
Translations
  • ar
  • bn
  • cs
  • da
  • de
  • el
  • en
  • es
  • fa
  • fr
  • he
  • hi
  • hu
  • id
  • it
  • ja
  • ko
  • nb
  • nl
  • pl
  • pt-br
  • ro
  • ru
  • sv
  • th
  • tr
  • uk
  • ur
  • vi
  • zh-cn

Open Graph

url
https://xeve.ai
title
AI Girlfriends – Video, Chat & AI Sexting
description
Dive into ultra-realistic AI porn with interactive videos and realistic chat experiences. Perfect for companionship and fantasy.

Social

Contact

Address
st AI companion for your use case.Jay Web Development & Services, 117/229/10534

Registration

Registrar
NameCheap, Inc.
Created
2024-08-26
Expires
2026-08-26 98 days left
Updated
2024-12-06
Name servers
  • pdns1.registrar-servers.com
  • pdns2.registrar-servers.com

DNS records live

NS
  • pdns1.registrar-servers.com
  • pdns2.registrar-servers.com
MX
  • 10 mx.zoho.com
  • 10 mx3.zoho.com
  • 20 mx2.zoho.com
TXT
Show 5 TXT records
  • hosting-site=personai-86161
  • blogarama-694a533b-93c9-4e8f-82ff-9a070d80dbe9
  • zoho-verification=zb92828058.zmverify.zoho.com
  • google-site-verification=JSDjaKzTP1cKRDc02iA6AqWnzbMfCC_2gUFqvFu3vO4
  • firebase=personai-86161

Email authentication weak

SPF
v=spf1 include:_spf.firebasemail.com include:zohomail.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

WR3
from 2026-04-04 to 2026-07-03
Expires in 45 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://xeve.ai/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • permissions-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing content type protection
  • missing Referrer Policy
Header values
x-frame-options
DENY
permissions-policy
microphone=(self)
content-security-policy
default-src 'self'; script-src 'self' 'sha256-R58eZk5zfavyaZ7fLpu1381fTxqCkmEpR/Nc++O369g=' 'sha256-1jAmyYXcRq6zFldLe/GCgIDJBiOONdXjTLgEFMDnDSM=' https://www.googletagmanager.com https://www.google-analytics.com https://apis.google.com; connect-src 'self' https://firebasestorage.googleapis.com https://apis.google.com https://*.google-analytics.com https://nonprodlb.xeve.ai https://lb.xeve.ai https://www.google-analytics.com https://securetoken.googleapis.com https://identitytoolkit.googleapis.com https://europe-west1-nonprodpersonai.cloudfunctions.net https://europe-west1-personai-86161.cloudfunctions.net https://*.b-cdn.net https://api.emailjs.com; media-src 'self' https://firebasestorage.googleapis.com https://*.b-cdn.net blob:; img-src 'self' data: https://*.b-cdn.net https://storage.googleapis.com https://www.googletagmanager.com https://firebasestorage.googleapis.com; form-action 'self' https://*.ccbill.com; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; fra
strict-transport-security
max-age=31536000; includeSubDomains; preload
cross-origin-opener-policy
same-origin

Links to (4)

Linked from (5)