Redirects to www.line.me

That is the address visitors actually land on, so the certificate, security headers, and public files were checked there. Some sites serve a different certificate on each address.

68 / 100
line.me just checked
Pass 10 Warning 9 Critical 1

Risk signals

Risk signals 1 found

Have a look at the items below. A signal does not prove anything is wrong, but it is reason enough to look twice before entering personal or payment details.

Encrypted connection No HTTPS

A site running normally today rarely lacks HTTPS. Do not enter personal or payment details on this address.

Signs of real operation mail configured · SPF present

Mail is properly configured too — not something hastily built sites usually bother with.

Who serves this site

DNS provider NAVER

DNS records are managed here — this is where you log in to add or change them.

ns2.naver.jp · ans1.linecorp.com · ans2.linecorp.com
CDN / edge Amazon CloudFront

Requests pass through this layer before reaching the real server. It also hides the origin from visitors.

Origin host (estimated) Amazon CloudFront (hidden behind it)

Estimated from the IP registration. A CDN in front makes the true origin invisible from outside, which is the safer arrangement.

IP 147.92.243.206
Mail provider mx1-common.line-apps.com

This service handles mail for the domain. Follow its documentation when setting SPF and DMARC.

Certificate & encryption

Certificate expiry 156 days left (2027-01-02)

Plenty of validity left.

Issued by Amazon
Certificate coverage *.line.me, *.wongnai.com, *.line-scdn.net, *.frenz.world and 4

This domain is covered by the certificate.

Legacy TLS TLS 1.0/1.1 disabled

Obsolete protocol versions are switched off.

Email security (anti-spoofing)

SPF Configured · DNS lookups 4/10 max

A sender policy is published and closed off correctly.

v=spf1 include:naver.com include:spf.naver.jp ip4:203.104.136.0/24 ip4:147.92.128.0/17 in…
DMARC p=none

The policy only monitors — spoofed mail is still delivered.

v=DMARC1; p=none; fo=s; rua=mailto:[email protected]; pct=100
How to fix
Watch the reports for a few days, then raise the policy to p=quarantine.
DKIM Found: google

Outgoing mail is signed, so recipients can verify it was not forged.

Mail servers (MX) 100 mx2-common.line-apps.com. · 100 mx3-common.line-apps.com. · 10 mx-common.line-apps.com.

These servers receive mail for the domain.

MTA-STS Not enabled

Most mail is still encrypted without it, but nothing enforces it. Optional.

TLS-RPT Not enabled

There is no channel to report failed mail encryption. Optional.

Mail transport encryption (STARTTLS) Not supported (mx-common.line-apps.com)

Mail may travel in plain text and could be read along the way.

How to fix
Install a TLS certificate on the mail server and enable STARTTLS.

DNS configuration

CAA Not set

Any certificate authority in the world may issue a certificate for this name.

How to fix
Add a CAA record, for example: 0 issue "letsencrypt.org"
DNSSEC Not enabled

DNS answers cannot be verified against tampering. Not mandatory, but worth enabling.

How to fix
Most registrars enable DNSSEC with a single switch.
DNS propagation Consistent worldwide

All four resolvers queried return the same address.

Google no answer · Cloudflare no answer · Quad9 no answer · KT no answer

HTTP security headers

HSTS Not set

Without HSTS, a first visit over plain HTTP can be intercepted.

How to fix
add_header Strict-Transport-Security "max-age=31536000" always;
CSP Not set

No policy limits which scripts may run, which is the main defence against XSS.

How to fix
add_header Content-Security-Policy "default-src 'self'" always;
MIME sniffing protection Not set

Browsers may guess file types and execute something unintended.

How to fix
add_header X-Content-Type-Options "nosniff" always;
Clickjacking protection Not set

Another site can frame your pages and trick users into clicking.

How to fix
add_header X-Frame-Options "SAMEORIGIN" always;
Referrer policy Not set

Full URLs may leak to other sites when visitors click away.

How to fix
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
Server version disclosure CloudFront

The server version is not advertised.

Response time 25ms

The first byte arrives quickly.

Public files & access

robots.txt Not set

No crawler rules published. Not required.

security.txt Not set

There is no official channel to report a vulnerability. Optional.

Sitemap Not set

Search engines have to discover pages by following links.

How to fix
Publish sitemap.xml and reference it from robots.txt with a Sitemap: line.
HTTP → HTTPS redirect OK (301)

Plain HTTP requests are sent to the encrypted address.

Only public information is read (DNS records, certificates, HTTP responses). Nothing is logged in, and no load is placed on the site.

© 2026 WebsiteInfo