coinmate.io security report
Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.
76risk
Critical
Exposed services or known CVEs need attention now.
1Critical
2High
3Medium
5Low
1Info
Collected 2.6sfrom cache
- Certificate Transparency26
- DNS resolution42
- Network ownership0
- CDN / WAF detection0
- Exposed ports & CVEs60
- Registration
- DNS posture2
- Email authentication2
- Certificate
- Security headers5
- Archived URLs
- Analysis12
- noteFound 26 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
- noteCertificate inspection is unavailable in this runtime.
- noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
- noteCDN/WAF detection is unavailable in this runtime.
- noteNo registration data: RDAP has no record at this level.
- note3 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://coinmate.io/enstatus 200time 770msstack cloudflare
- ✓http:// redirects to https://
- ✓Strict-Transport-Securitymax-age=31536000
- ✓Content-Security-Policydefault-src 'self'; style-src 'self' 'unsafe-inline' surveys-static-prd.survicate-cdn.com fonts.googleapis.com; font-src 'self' data: fonts.gstatic.com surveys-…
- ✓Clickjacking protectionSAMEORIGIN
- ✓X-Content-Type-Optionsnosniff
- ✓Referrer-Policystrict-origin-when-cross-origin
- –Permissions-Policyoptional
- ✓security.txt published
- ✓Receives mail via 5 servers
- !SPFends in ~allv=spf1 include:_spf.google.com ~all
- ✓DMARCp=quarantinev=DMARC1; p=quarantine;
- !MTA-STSinbound mail can be downgraded to plaintext
- ✓DNSSECanswers are signed and validated
- ✓CAA0 iodef "mailto:abuse@coinmate.io" · 0 issue "amazon.com" · 0 issue "amazonaws.com" · 0 issue "amazontrust.com" · 0 issue "awstrust.com" · 0 issue "comodoca.com" · 0 issue "digicert.com; cansignhttpexchanges=yes" · 0 issue "letsencrypt.org" · 0 issue "pki.goog; cansignhttpexchanges=yes" · 0 issue "sectigo.com" · 0 issue "ssl.com" · 0 issuewild "amazon.com" · 0 issuewild "amazonaws.com" · 0 issuewild "amazontrust.com" · 0 issuewild "awstrust.com" · 0 issuewild "comodoca.com" · 0 issuewild "digicert.com; cansignhttpexchanges=yes" · 0 issuewild "letsencrypt.org" · 0 issuewild "pki.goog; cansignhttpexchanges=yes" · 0 issuewild "sectigo.com" · 0 issuewild "ssl.com"
- ✓IPv6 (AAAA)
- ✓2 nameservers
| Address | Ports | CVEs | Edge | Network |
|---|---|---|---|---|
| 37.9.175.164 | 2122804433306331033115432+16 | 406 | direct | — |
| 104.26.0.82 coinmate.io +14 | 80443205320822083208620872096+3 | 0 | Cloudflare~ | — |
| 104.26.1.82 coinmate.io +14 | 80443205320822083208620872096+3 | 0 | Cloudflare~ | — |
| 172.67.71.55 coinmate.io +14 | 80443208220832086208720968080+2 | 0 | Cloudflare~ | — |
| 167.235.220.62 | 80443 | 0 | direct | — |
| 172.246.243.65 | 80443 | 0 | direct | — |
coinmate.iowww.coinmate.iostage.coinmate.ioauth-stage.coinmate.iodocs-stage.coinmate.iomock-stage.coinmate.iobinance-proxy.stage.coinmate.ioauth.coinmate.ioauth-sand.coinmate.ioairbank-api.sand.coinmate.iostatus.coinmate.ioblog.coinmate.iodocs.coinmate.iosand.coinmate.iowiki.coinmate.iostart.coinmate.iosatoshi.coinmate.iodocs-sand.coinmate.iomock-sand.coinmate.ioproblems-registry.coinmate.ior.brevo.coinmate.io
Archived URLs
Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.