hogum
gomacro.com

gomacro.com security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

70risk

Elevated

Several issues worth triaging this week.

0Critical
3High
7Medium
10Low
2Info
Collected 38.5sfrom cache
  1. Certificate Transparency12
  2. DNS resolution20
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs39
  6. Registration
  7. DNS posture2
  8. Email authentication2
  9. Certificate
  10. Security headers4
  11. Archived URLs
  12. Analysis22
  • noteFound 19 addresses; enriching the first 12.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • note1 host was identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://gomacro.com/status 200time 361msstack cloudflare
  • http:// redirects to https://
  • !Strict-Transport-Security
    max-age=7889238
  • Content-Security-Policy
    block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
  • Clickjacking protection
    DENY
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Cookie _shopify_y
    no Secure · no HttpOnly · SameSite=lax
  • Cookie _shopify_s
    no Secure · no HttpOnly · SameSite=lax
  • Cookie localization
    no Secure · no HttpOnly · SameSite=lax
  • Cookie cart_currency
    no Secure · no HttpOnly · SameSite=lax
  • Cookie _shopify_essential
    Secure · HttpOnly · SameSite=lax
  • Cookie _shopify_analytics
    Secure · HttpOnly · SameSite=lax
  • Cookie _shopify_marketing
    Secure · HttpOnly · SameSite=lax
  • Receives mail via 1 server
  • SPFends in -all
    v=spf1 a mx include:spf.protection.outlook.com include:_spf.salesforce.com include:amazonses.com include:spf.smtp2go.com include:relay.mailchannels.net include:spf.gotoresolve.com -all
  • DMARCp=quarantine
    v=DMARC1; p=quarantine; sp=none; adkim=s; aspf=s; rua=mailto:dmarc_rua@gomacro.com; ruf=mailto:dmarc_ruf@gomacro.com; fo=1;
  • !MTA-STSinbound mail can be downgraded to plaintext
  • Registered with GoDaddy.com, LLC21.3 years old
  • Registration expiry991 days
    2029-05-25
  • Transfer lock
    client delete prohibited, client renew prohibited, client transfer prohibited, client update prohibited
  • 2 nameservers at registry
AddressPortsCVEsEdgeNetwork
23.227.38.65
80443205220532082208320862087+5
0Cloudflare~
97.107.135.178
258044310256
2direct
185.3.93.228
2580443
2direct
170.187.131.209
2580443
2direct
15.197.225.128
80443
0direct
3.33.251.168
80443
0direct
100.49.0.246
80443
0direct
100.49.110.141
80443
0direct
13.35.163.128
80443
0direct
13.35.163.76
80443
0direct
13.35.163.64
80443
0direct
13.35.163.20
80443
0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.