20
Low Risk
2026-05-21 02:53:00
Security Issues Found
- ⚠️[MEDIUM] 缺少 HTTP 安全头
Recommendations
- 💡添加 DMARC 记录增强邮件安全
- 💡配置 Web 服务器添加这些安全头
🌐Domain Info
Targetcanny.io
Registeredcanny.io
TLD.io
🛡️Threat Intelligence (7 platforms)
BlacklistNot Blacklisted
Malware0
Phishing0
Abuse Score0/100
🐛Vulnerabilities Found (1)
MEDIUM缺少 HTTP 安全头
缺少以下安全头: X-XSS-Protection, Permissions-Policy
Fix: 配置 Web 服务器添加这些安全头
🔌Open Ports (2)
80
http
443
https
🌐DNS Records
A: 3.175.207.8
A: 3.175.207.81
A: 3.175.207.120
A: 3.175.207.43
AAAA: 2600:9000:2939:1000:0:1a32:efc0:93a1
AAAA: 2600:9000:2939:e000:0:1a32:efc0:93a1
AAAA: 2600:9000:2939:5400:0:1a32:efc0:93a1
AAAA: 2600:9000:2939:a000:0:1a32:efc0:93a1
AAAA: 2600:9000:2939:8800:0:1a32:efc0:93a1
AAAA: 2600:9000:2939:d600:0:1a32:efc0:93a1
AAAA: 2600:9000:2939:ea00:0:1a32:efc0:93a1
AAAA: 2600:9000:2939:7a00:0:1a32:efc0:93a1
MX: 1 aspmx.l.google.com.
MX: 10 alt3.aspmx.l.google.com.
MX: 10 alt4.aspmx.l.google.com.
MX: 5 alt1.aspmx.l.google.com.
MX: 5 alt2.aspmx.l.google.com.
NS: ns-1321.awsdns-37.org.
NS: ns-1655.awsdns-14.co.uk.
NS: ns-252.awsdns-31.com.
NS: ns-669.awsdns-19.net.
TXT: "MS=ms35415925"
TXT: "ahrefs-site-verification_5e69e6997804ed8a30a39d39275b9fbf0de36ec5a5637808d74d4894bd76d9ce"
TXT: "anthropic-domain-verification-g9kfsx=Wqt2Ia7dl8hf4MjgxvlTOOxui"
TXT: "apple-domain-verification=90WAYflsx2QFb0Na"
TXT: "google-site-verification=hutYg6OBDqx9fLFmeEqY4o0gjWPw2rkFt3-Sp2wbMQc"
TXT: "google-site-verification=sgCUxCuZgnknnR8A2Rfped-nxsHpFn-DgXcQaLvoTkc"
TXT: "hubspot-developer-verification=Y2MyYzI1ODAtMjBkNy00ZTc2LTkyNjQtNzczNzA2OWRjNDQ2"
TXT: "hubspot-developer-verification=ZTI0MmUwMTktYjlkOC00NjcwLWFiNGEtOWExZjMzNjRjNDQ0"
TXT: "v=spf1 include:amazonses.com include:mailgun.org include:servers.mcsv.net include:_spf.google.com include:5705808.spf01.hubspotemail.net -all"
SOA: ns-669.awsdns-19.net. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400
📋HTTP Headers
X-Frame-Options: sameorigin
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Content-Security-Policy: frame-ancestors 'self'; base-uri 'self'; default-src 'self' https://canny.io https://*.canny.io; child-src 'self' blob:
Referrer-Policy: strict-origin