cloudfare.com
Issues to address (2)
Header: content-security-policy
CSP restricts which sources of scripts, styles, and other content the browser will load — the strongest defense against XSS.
CAA records
No CAA records published. CAA records restrict which Certificate Authorities can issue certificates for your domain, reducing the risk of mis-issuance.
Passed checks (13)
Port scan summary
Checked 12 common ports on 172.67.211.231. Open: 80/HTTP, 443/HTTPS.
SPF record
SPF record is present and uses an enforcing policy.
DMARC policy
DMARC is published with a strict reject policy.
DKIM detection
DKIM key detected at selector(s): google, selector2, k1, s2, mail, s1, default, selector1.
MX records
MX records present (4). Mail will be routed to mailstream-canary.mxrecord.io.
Nameserver redundancy
2 nameservers configured.
TLS certificate
Valid certificate issued by WE1, expires in 33 days. Protocol: TLSv1.3.
Header: strict-transport-security
strict-transport-security is set.
Header: x-frame-options
x-frame-options is set.
Header: x-content-type-options
x-content-type-options is set.
Header: referrer-policy
referrer-policy is set.
Header: permissions-policy
permissions-policy is set.
HTTP → HTTPS redirect
HTTP requests redirect to HTTPS.