xter.io
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Next.js
Third-party hosts loaded (1)
- images.prismic.io×34
Social
Contact
DNS records live
- NS
-
- ns-1336.awsdns-39.org
- ns-1928.awsdns-49.co.uk
- ns-364.awsdns-45.com
- ns-781.awsdns-33.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
0eb6b041a4c26b62d51f8c99ace3f5d4fa912a3ef2e683a72dbf90db46bc8f08
Email authentication strong
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCZd/WvWoyY4U1xTNkQS4iNau557/0/kMe8HENsldfIPT59+MAQ2QSmlCYM/xpMiX5MGNgiroc0N/r7k+Nt6j…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M01
Expires in 296 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; connect-src 'self' https://xterio.cdn.prismic.io; script-src 'self' 'unsafe-eval' 'unsafe-inline' netlify-rum.netlify.app; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https://images.prismic.io https://superrbimages-1fd4f.kxcdn.com; font-src 'self' data:; object-src data: 'unsafe-eval'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://xterio.prismic.io;
Links to (10)
- bitget.com×2
- bybit.com×2
- htx.com×2
- kucoin.com×2
- linkedin.com×2
- medium.com×2
- mexc.com×2
- superrb.com×2
- t.me×2
- x.com×2