toneitup.com security report
Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.
36risk
Moderate
Some surface to tighten, nothing urgent.
0Critical
0High
4Medium
16Low
2Info
Collected 20.8sfrom cache
Domain—
unavailable
- Certificate Transparency22
- DNS resolution31
- Network ownership0
- CDN / WAF detection0
- Exposed ports & CVEs40
- Registration
- DNS posture2
- Email authentication2
- Certificate
- Security headers4
- Archived URLs
- Analysis22
- noteFound 22 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
- noteFound 23 addresses; enriching the first 12.
- noteCertificate inspection is unavailable in this runtime.
- noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
- noteCDN/WAF detection is unavailable in this runtime.
- noteRegistration did not complete (Too many subrequests by single Worker invocation. To configure this limit, refer to https://developers.cloudflare.com/workers/wrangler/configuration/#limits). Results below are partial.
- note2 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://my.toneitup.com/status 200time 839msstack cloudflare
- –http:// redirects to https://port 80 did not answer
- !Strict-Transport-Securitymax-age=7889238
- ✓Content-Security-Policyblock-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
- ✓Clickjacking protectionDENY
- ✓X-Content-Type-Optionsnosniff
- ✗Referrer-Policy
- –Permissions-Policyoptional
- –security.txt publishedoptional — tells researchers where to report bugs
- ✗Cookie _shopify_yno Secure · no HttpOnly · SameSite=lax
- ✗Cookie _shopify_sno Secure · no HttpOnly · SameSite=lax
- ✗Cookie localizationno Secure · no HttpOnly · SameSite=lax
- ✗Cookie cart_currencyno Secure · no HttpOnly · SameSite=lax
- ✓Cookie _shopify_essentialSecure · HttpOnly · SameSite=lax
- ✓Cookie _shopify_analyticsSecure · HttpOnly · SameSite=lax
- ✓Cookie _shopify_marketingSecure · HttpOnly · SameSite=lax
- ✓Receives mail via 7 servers
- !SPFends in ~allv=spf1 include:mailgun.org include:_spf.google.com include:send.toneitup.com ~all
- ✓DMARCp=quarantinev=DMARC1; p=quarantine;
- !MTA-STSinbound mail can be downgraded to plaintext
- !DNSSECanswers can be forged
- –CAAany CA may issue
- ✓IPv6 (AAAA)
- ✓2 nameservers
| Address | Ports | CVEs | Edge | Network |
|---|---|---|---|---|
| 104.21.16.74 toneitup.com +4 | 80443205220532082208320862087+5 | 0 | Cloudflare~ | — |
| 172.67.166.231 toneitup.com +4 | 80443205220532082208320862087+5 | 0 | Cloudflare~ | — |
| 44.224.68.31 | 80443 | 0 | direct | — |
| 18.162.234.233 | 80443 | 0 | direct | — |
| 32.187.24.222 | 80443 | 0 | direct | — |
| 63.34.141.205 | 80443 | 0 | direct | — |
| 52.35.70.36 | 443 | 0 | direct | — |
| 32.188.51.0 | 443 | 0 | direct | — |
| 13.224.245.56 | 80 | 0 | direct | — |
| 13.224.245.52 | 80 | 0 | direct | — |
| 13.224.245.40 | 80 | 0 | direct | — |
| 13.224.245.95 | 80 | 0 | direct | — |
toneitup.comlr-dev.toneitup.comlr-stg.toneitup.comstaging.toneitup.comauth-dev.toneitup.comshop-beta.toneitup.comdev-subhub.toneitup.comapi-staging.toneitup.comstaging-subhub.toneitup.comauth.toneitup.comlr.toneitup.commy.toneitup.comcms.toneitup.comdemo.toneitup.comhelp.toneitup.comlink.toneitup.comshop.toneitup.comyour.toneitup.comassets.toneitup.comshopifydev.toneitup.comcustomermanagement.toneitup.com
Archived URLs
Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.