6things to fix
✗No DMARC record - domain is open to spoofing.▸
Publish a TXT record at _dmarc starting with v=DMARC1; p=none; rua=mailto:you@yourdomain, then tighten it to reject once senders pass.
Read the guide →!DNSSEC not enabled - enable it to prevent DNS spoofing.▸
Turn on DNSSEC at your DNS host, then publish the DS record at your registrar to complete the chain of trust.
Read the guide →!No HSTS header - add Strict-Transport-Security.▸
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every response, at your server or CDN edge.
Read the guide →!No Content-Security-Policy header.▸
Add a Content-Security-Policy. Start in Content-Security-Policy-Report-Only mode, refine it, then enforce.
Read the guide →!Missing X-Content-Type-Options: nosniff.▸
Add the header X-Content-Type-Options: nosniff to stop browsers MIME-sniffing responses.
Read the guide →!HTTP does not redirect to HTTPS.▸
Redirect all HTTP traffic to HTTPS with a 301. Most hosts and CDNs have a one-click 'Always use HTTPS' setting.
DNS records
A104.21.17.48
172.67.222.78
AAAA2606:4700:3035::6815:1130
2606:4700:3030::ac43:de4e
Nameserverselaine.ns.cloudflare.com.
patryk.ns.cloudflare.com.
MXdoes not receive emailNo mail
SOAelaine.ns.cloudflare.com. dns.cloudflare.com. 2412666148 10000 2400 604800 1800
Mail authentication
SPFmissing-
DMARCmissingFail
DKIMnot detected on common selectors-
DNSSEC
ZoneOff
IP intelligence
Primary IP104.21.17.48
TLS certificate
CertificateGoogle Trust Services · expires 2026-10-16 (45d)Valid
HTTP security headers
HTTPS redirectNo
HSTSNo
CSPNo
X-Content-TypeNo
X-Frame-OptionsNo
Referrer-PolicyNo
Permissions-PolicyNo
Servercloudflare
Add this badge to your site
<a href="https://nattvakt.com/report/chatinbrowser.com"><img src="https://nattvakt.com/badge/chatinbrowser.com.svg" alt="Domain health"></a>