97 / 100
x.com checked just now · check again now
Pass 22 Warning 1 Critical 0

Risk signals

Risk signals None found

Nothing stood out. That is not a guarantee of safety — only public information was examined.

Domain age 33 years (1993-04-02 registered)

The domain has been maintained for a long time.

Certificate issued 62 days ago

Certificates are renewed regularly, so a recent date on its own is normal.

Signs of real operation mail configured · SPF present

Mail is properly configured too — not something hastily built sites usually bother with.

Who serves this site

DNS provider a.r10.twtrdns.net

DNS records are managed here — this is where you log in to add or change them.

a.r10.twtrdns.net · a.u10.twtrdns.net · b.r10.twtrdns.net
CDN / edge Cloudflare

Requests pass through this layer before reaching the real server. It also hides the origin from visitors.

Origin host (estimated) Cloudflare (hidden behind it)

Estimated from the IP registration. A CDN in front makes the true origin invisible from outside, which is the safer arrangement.

IP 172.66.0.227
Mail provider Google

This service handles mail for the domain. Follow its documentation when setting SPF and DMARC.

Certificate & encryption

Certificate expiry 27 days left (2026-08-26)

Plenty of validity left.

Issued by Let's Encrypt
Certificate coverage *.live.x.com, *.watch.x.com, *.x.com, cdn.syndication.x.com and 2

This domain is covered by the certificate.

Legacy TLS TLS 1.0/1.1 disabled

Obsolete protocol versions are switched off.

Email security (anti-spoofing)

SPF Configured · DNS lookups 5/10 max

A sender policy is published and closed off correctly.

v=spf1 ip4:199.16.156.0/22 ip4:199.59.148.0/22 include:_spf.google.com include:_spf.sales…
DMARC p=reject

Spoofed mail is quarantined or rejected.

v=DMARC1; p=reject; rua=mailto:[email protected].…
DKIM Found: google

Outgoing mail is signed, so recipients can verify it was not forged.

Mail servers (MX) 1 aspmx.l.google.com. · 10 alt3.aspmx.l.google.com. · 10 alt4.aspmx.l.google.com.

These servers receive mail for the domain.

MTA-STS Not enabled

Most mail is still encrypted without it, but nothing enforces it. Optional.

TLS-RPT Not enabled

There is no channel to report failed mail encryption. Optional.

Mail transport encryption (STARTTLS) Supported (aspmx.l.google.com)

Mail to this domain travels over an encrypted channel. Verified by connecting to the actual server.

DNS configuration

CAA Not set

Any certificate authority in the world may issue a certificate for this name.

How to fix
Add a CAA record, for example: 0 issue "letsencrypt.org"
DNSSEC Not enabled

DNS answers cannot be verified against tampering. Not mandatory, but worth enabling.

How to fix
Most registrars enable DNSSEC with a single switch.
DNS propagation Consistent worldwide

All four resolvers queried return the same address.

Google no answer · Cloudflare no answer · Quad9 no answer · KT no answer

HTTP security headers

HSTS Configured

Browsers are told to use HTTPS only.

CSP Configured

Script sources are restricted.

MIME sniffing protection Configured

Browsers will not second-guess declared file types.

Clickjacking protection Configured

Other sites cannot silently frame your pages.

Referrer policy Configured

Referrer information sent to other sites is limited.

Server version disclosure cloudflare envoy

The server version is not advertised.

Response time 264ms

The first byte arrives quickly.

Public files & access

robots.txt information leak Disallow 61건 · no sensitive paths

No sensitive-looking paths are listed.

security.txt Present

A public contact is published for reporting security issues.

Sitemap Not set

Search engines have to discover pages by following links.

How to fix
Publish sitemap.xml and reference it from robots.txt with a Sitemap: line.
HTTP → HTTPS redirect OK (301)

Plain HTTP requests are sent to the encrypted address.

Domain registration

Domain expiry 2034-10-20 (3004 days left)

Registration has time left.

Registered 1993-04-02

Only public information is read (DNS records, certificates, HTTP responses). Nothing is logged in, and no load is placed on the site.

© 2026 WebsiteInfo