dhsaestheticism.com
F【49】导航网!
Built with
No platform, CMS or framework detected. Detection is passive: it only sees what a site exposes in its HTML, headers and cookies, so custom or well-hidden stacks show up as nothing rather than as a guess.
Overview
- Status
- alive
- Registered
- not looked up yet
- First seen here
- 2026-09-21
- Security grade
- F (40/100, from headers & TLS)
- Privacy score
- 100/100 (0 third-party script hosts, 0 tracking/marketing services)
- Hosting
- unknown
- Linked to from
- 1 other sites seen so far
What to fix
- Add Strict-Transport-Security
Header: Strict-Transport-Security: max-age=31536000; includeSubDomains - Add a Content-Security-Policy
Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test. - Add X-Content-Type-Options
Header: X-Content-Type-Options: nosniff - Prevent clickjacking
Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive). - Add a Referrer-Policy
Header: Referrer-Policy: strict-origin-when-cross-origin - Publish an SPF record
A DNS TXT record listing who may send email for this domain, which prevents spoofing. - Publish a DMARC record
A TXT record at _dmarc.<domain>; start with v=DMARC1; p=none; to monitor.
Security & email signals
- ✓ HTTPS
- ✗ HSTS
- ✗ Content-Security-Policy
- ✗ X-Content-Type-Options
- ✗ X-Frame-Options
- ✗ Referrer-Policy
- ✗ Permissions-Policy
- ✗ SPF record
- ✗ DMARC record
- ✗ DKIM record
- ✓ Cookies set securely
- ✓ Has real content (not an empty shell)
- ✓ Valid TLS certificate
Recent changes
- 2026-09-22: TLS expiry changed from "2026-11-04" to "2026-11-04"
- 2026-09-22: TLS expiry changed from "2026-11-04" to "2026-11-04"
- 2026-09-22: TLS expiry changed from "2026-11-04" to "2026-11-04"
- 2026-09-22: TLS expiry changed from "2026-11-04" to "2026-11-04"
- 2026-09-21: TLS expiry changed from "2026-11-04" to "2026-11-04"
- 2026-09-21: TLS expiry changed from "2026-11-04" to "2026-11-04"
Badge
Show this site's security grade in a README or footer:

<a href="https://webtelemetry.dev/site/dhsaestheticism.com"><img src="https://webtelemetry.dev/badge/dhsaestheticism.com.svg" alt="Security grade"></a>
Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.