83 / 100
nexon.com checked 1 min ago · check again now
Pass 15 Warning 6 Critical 0

Risk signals

Risk signals None found

Nothing stood out. That is not a guarantee of safety — only public information was examined.

Domain age 30 years (1996-03-28 registered)

The domain has been maintained for a long time.

Certificate issued 204 days ago

Certificates are renewed regularly, so a recent date on its own is normal.

Signs of real operation mail configured · SPF present

Mail is properly configured too — not something hastily built sites usually bother with.

Who serves this site

DNS provider a7-67.akam.net

DNS records are managed here — this is where you log in to add or change them.

a7-67.akam.net · a4-66.akam.net · a13-67.akam.net
CDN / edge unknown

Requests pass through this layer before reaching the real server. It also hides the origin from visitors.

Origin host (estimated) Amazon AWS

Estimated from the IP registration. A CDN in front makes the true origin invisible from outside, which is the safer arrangement.

IP 52.78.145.30 · 52.78.153.209
Mail provider nexon-com.mail.protection.outlook.com

This service handles mail for the domain. Follow its documentation when setting SPF and DMARC.

Certificate & encryption

Certificate expiry 190 days left (2027-02-05)

Plenty of validity left.

Issued by Amazon
Certificate coverage *.nexon.com, nexon.com

This domain is covered by the certificate.

Legacy TLS TLS 1.0/1.1 disabled

Obsolete protocol versions are switched off.

Email security (anti-spoofing)

SPF Configured · DNS lookups 6/10 max

A sender policy is published and closed off correctly.

v=spf1 include:spf.protection.outlook.com include:amazonses.com include:_spf.nexon.com in…
DMARC p=quarantine

Spoofed mail is quarantined or rejected.

v=DMARC1; p=quarantine; pct=100; aspf=s; rua=mailto:[email protected]
DKIM Found: google

Outgoing mail is signed, so recipients can verify it was not forged.

Mail servers (MX) 10 nexon-com.mail.protection.outlook.com.

These servers receive mail for the domain.

MTA-STS Not enabled

Most mail is still encrypted without it, but nothing enforces it. Optional.

TLS-RPT Not enabled

There is no channel to report failed mail encryption. Optional.

Mail transport encryption (STARTTLS) Supported (nexon-com.mail.protection.outlook.com)

Mail to this domain travels over an encrypted channel. Verified by connecting to the actual server.

DNS configuration

CAA Not set

Any certificate authority in the world may issue a certificate for this name.

How to fix
Add a CAA record, for example: 0 issue "letsencrypt.org"
DNSSEC Not enabled

DNS answers cannot be verified against tampering. Not mandatory, but worth enabling.

How to fix
Most registrars enable DNSSEC with a single switch.
DNS propagation Consistent worldwide

All four resolvers queried return the same address.

Google 52.78.145.30/52.78.153.209/52.78.153.209 · Cloudflare no answer · Quad9 no answer · KT no answer

HTTP security headers

HSTS Not set

Without HSTS, a first visit over plain HTTP can be intercepted.

How to fix
add_header Strict-Transport-Security "max-age=31536000" always;
CSP Not set

No policy limits which scripts may run, which is the main defence against XSS.

How to fix
add_header Content-Security-Policy "default-src 'self'" always;
MIME sniffing protection Not set

Browsers may guess file types and execute something unintended.

How to fix
add_header X-Content-Type-Options "nosniff" always;
Clickjacking protection Not set

Another site can frame your pages and trick users into clicking.

How to fix
add_header X-Frame-Options "SAMEORIGIN" always;
Referrer policy Not set

Full URLs may leak to other sites when visitors click away.

How to fix
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
Server version disclosure unknown

The server version is not advertised.

Response time 29ms

The first byte arrives quickly.

Public files & access

robots.txt Not set

No crawler rules published. Not required.

security.txt Not set

There is no official channel to report a vulnerability. Optional.

Sitemap Not set

Search engines have to discover pages by following links.

How to fix
Publish sitemap.xml and reference it from robots.txt with a Sitemap: line.
HTTP → HTTPS redirect OK (302)

Plain HTTP requests are sent to the encrypted address.

Domain registration

Domain expiry 2036-03-29 (3530 days left)

Registration has time left.

Registered 1996-03-28

Only public information is read (DNS records, certificates, HTTP responses). Nothing is logged in, and no load is placed on the site.

© 2026 WebsiteInfo