webtelemetry.dev

nic.ai

F

.ai Official Registry Operator Website

Last scanned 7 h agoCompare with another site →

Built with

Frontend framework
React

Overview

Status
alive
Registered
not looked up yet
First seen here
2026-09-21
Security grade
F (55/100, from headers & TLS)
Privacy score
90/100 (0 third-party script hosts, 0 tracking/marketing services)
Hosting
unknown
Linked to from
4 other sites seen so far

What to fix

  1. Add a Content-Security-Policy
    Limits which scripts can run — the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  2. Prevent clickjacking
    Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive).
  3. Add a Referrer-Policy
    Header: Referrer-Policy: strict-origin-when-cross-origin
  4. Mark cookies Secure and HttpOnly
    At least one cookie is sent without these flags, exposing it to interception or scripts.
  5. Publish an SPF record
    A DNS TXT record listing who may send email for this domain — prevents spoofing.
  6. Publish a DMARC record
    A TXT record at _dmarc.<domain>; start with v=DMARC1; p=none; to monitor.

Security & email signals

Recent changes

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for nic.ai
<a href="https://webtelemetry.dev/site/nic.ai"><img src="https://webtelemetry.dev/badge/nic.ai.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.