ybera.com

.com crawl

First seen 2026-04-16 · Last seen 2026-05-20 · ok HTTP/1.1 200 5039 ms crawled 2026-05-11

US · 104.26.0.250 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Ybera.com
Description
B2C Store - A evolução da Loja Ybera
Language
pt-BR

Technology

Server
Kestrel
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts
Third-party hosts loaded (11)
  • lojaybera.fbitsstatic.net×67
  • fonts.googleapis.com×2
  • widget.gotolstoy.com×2
  • bflow.b2.club×1
  • fonts.gstatic.com×1
  • play.gotolstoy.com×1
  • provider-public-assets.pagaleve.com.br×1
  • static.fbits.net×1
  • static.zdassets.com×1
  • unpkg.com×1
  • www.googletagmanager.com×1

Registration

Registrar
GoDaddy.com, LLC
Created
2004-11-19
Expires
2026-11-19 182 days left
Updated
2025-11-20
Name servers
  • cass.ns.cloudflare.com
  • odin.ns.cloudflare.com

DNS records live

NS
  • cass.ns.cloudflare.com
  • odin.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • sky-domain-verification=19787add3511db04866608b2b56e8f67a9
  • tiktok-developers-site-verification=wwSQ0XNvafjpFqYk8sEgcTEFDC0dJ7Wh
Verified for
  • Google
  • Meta

Email authentication partial

SPF
v=spf1 include:_spf.google.com include:shops.shopify.com include:spf.skymail.net.br include:mail.zendesk.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:hello@ybera.com
policy: none (monitoring only)
DKIM
Show 5 DKIM selectors
  • default: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzqBH81beB2yFI/oXmS7o4x9GcPOU7txB4ZP1xfvvdcDJWc2llM7PKoeUVWkdtt+9bRDHmPqUyZ6SMR…
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmNmRG7qxi5V4ZMlh81ZwOvRAq5LLqFYeJbSMNQedndmFZDRo54HoeBt507L/xYlfLGf6dQSCu+XvvM…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyPBQ+2Q2pw9CKwPDTzlSTmiZkV35EBkANY6aMlxImu97AHof5BkIz7WOOL6OYTrY3FDZsrytcrNAIYVNci…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwLJjAPA72MRTGwwMg7L8ovYtwvR2MWjIyoCvZkVqrZBO1Kr7guia8roXJp9rvnjggI5pe7g6If/b7Ninve…
selectors probed

Certificate (current)

WE1
from 2026-05-02 to 2026-07-31
Expires in 72 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.ybera.com/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
Header values
permissions-policy
Permissions-Policy:=(), ambient-light-sensor=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), picture-in-picture=(self), speaker=(self), usb=(self), vr=(self), Permissions-Policy:=(), ambient-light-sensor=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), picture-in-picture=(self), speaker=(self), usb=(self), vr=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' ybera.com *.ybera.com wake-components.fbitsstatic.net lojaybera.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com b2cpreproduction.azurewebsites.net *.azurewebsites.net *.hotjar.com b2c-orders.azurewebsites.net *.microsoft.com *.clarity.ms
strict-transport-security
max-age=31536000 ; includeSubDomains ; preload

Linked from (6)