DNS & HTTP Analysis for bandcamp.com
- Details
- Category: Tool Processing Reports
Processing Domain bandcamp.com on 18/04/2020 20:22:29
- This tool is available free to use at GENSupport
- Help and Support for your DNS or HTTP issues available on our Forum
- Whenever you see a clicking on it will take you to more help
- The version of the data model that was used in this report is 1.008
- The version that produced this report is 1.023b
Processing DNS Records
Basic Checks
Here we check the basic functioning and security of your DNS
- Zone Queries 5 Record Types and 19 Records Found
- Zone Transfer Failed
- Zone Dump
- TXT
- _dmarc.bandcamp.com. TTL 1800 "v=DMARC1; p=none; rua=mailto:This email address is being protected from spambots. You need JavaScript enabled to view it."
- bandcamp.com. TTL 1800 "_globalsign-domain-verification=K1SffUM-LqrwICv_cd6cQX5yGwMXfJxwaEDgfO52J-"
- bandcamp.com. TTL 1800 "google-site-verification=R2K3ueaK09kESoG_YBuvOdRI7KWlKTgJket4pCrObTs"
- bandcamp.com. TTL 1800 "google-site-verification=n7VFVIsha5YafmTLSe77JvVFOMw95jU5S5BQRRL_6Qc"
- bandcamp.com. TTL 1800 "v=spf1 include:sendgrid.net include:_spf.google.com include:spf-basic.fogbugz.com ~all"
- A
- bandcamp.com. TTL 1800 151.101.1.28
- bandcamp.com. TTL 1800 151.101.129.28
- bandcamp.com. TTL 1800 151.101.193.28
- bandcamp.com. TTL 1800 151.101.65.28
- SOA
- bandcamp.com. TTL 1800 dns1.easydns.com. zone.easydns.com. 2020041601 3600 600 2419200 3600
- MX
- bandcamp.com. TTL 86400 1 aspmx.l.google.com.
- bandcamp.com. TTL 86400 10 aspmx2.googlemail.com.
- bandcamp.com. TTL 86400 10 aspmx3.googlemail.com.
- bandcamp.com. TTL 86400 5 alt1.aspmx.l.google.com.
- bandcamp.com. TTL 86400 5 alt2.aspmx.l.google.com.
- NS
- bandcamp.com. TTL 86400 dns3.easydns.org.
- bandcamp.com. TTL 86400 dns4.easydns.info.
- bandcamp.com. TTL 86400 ns-321.awsdns-40.com.
- bandcamp.com. TTL 86400 ns-958.awsdns-55.net.
Nameservers
Here we check the setup of your nameservers. All nameservers on your domain should be listed in the zone and returned in an ANY query along with corresponding A and/or AAAA records resolving their address.
- dns3.easydns.org 64.68.196.10 Found and Match. (Missing from Zone Address Records )
- ns-958.awsdns-55.net 205.251.195.190 Found and Match. (Missing from Zone Address Records )
- dns4.easydns.info 64.68.197.10 Found and Match. (Missing from Zone Address Records )
- ns-321.awsdns-40.com 205.251.193.65 Found and Match. (Missing from Zone Address Records )
- All Name Servers on Different Subnets
Processing 5 TXT Records
DMARC Record:
The DMARC Record defines how MTA's should response when parsing DKIM and SPF records
- v=dmarc1 (The Version of this record)
- p=none (The Policy to implement on FAIL)
- rua=mailto:This email address is being protected from spambots. You need JavaScript enabled to view it. (Reporting URI of aggregate reports)
Tinfoil Domain Verification
Another company promising to scan your website for vulnerabilities
- _globalsign-domain-verification=k1sffum-lqrwicv_cd6cqx5ygwmxfjxwaedgfo52j-
Google Domain Verification Record
This record is used by Google to validate domain ownership when setting up Google Analytics etc
- google-site-verification=r2k3ueak09kesog_ybuvodri7kwlktgjket4pcrobts
Google Domain Verification Record
This record is used by Google to validate domain ownership when setting up Google Analytics etc
- google-site-verification=n7vfvisha5yafmtlse77jvvfomw95ju5s5bqrrl_6qc
SPF Record:
The SPF Record defines which IP addresses are permitted to send email on this domain's behalf
- v=spf1 (The SPF Format Version Number)
- include:sendgrid.net (An Include - Additional look-ups required, some server's won't bother.)
- include:_spf.google.com (An Include - Additional look-ups required, some server's won't bother.)
- include:spf-basic.fogbugz.com (An Include - Additional look-ups required, some server's won't bother.)
- ~all (Permit other hosts but take note)
Processing 5 MX (Mail Exchanger) Records
These Records determine the servers (mail servers) responsible for handling your incomming email. Each service is given a priority and they will be used in that order. If all the priorities are the same then they will be used in a round-robin fashion
- Priority 1 handled by host aspmx.l.google.com. [173.194.76.27] Valid
- Email Handled By Google Corporation
- Port 25 (smtp) : Open
- Priority 10 handled by host aspmx2.googlemail.com. [209.85.233.27] Valid
- Email Handled By Google Corporation
- Port 25 (smtp) : Open
- Priority 10 handled by host aspmx3.googlemail.com. [142.250.4.27] Valid
- Email Handled By Google Corporation
- Port 25 (smtp) : Open
- Priority 5 handled by host alt1.aspmx.l.google.com. [209.85.233.26] Valid
- Email Handled By Google Corporation
- Port 25 (smtp) : Open
- Priority 5 handled by host alt2.aspmx.l.google.com. [142.250.4.26] Valid
- Email Handled By Google Corporation
- Port 25 (smtp) : Open
Processing 0 CNAME (Alias) Records
These records are aliases making one hostname relate to another. These are often used to match hosts back to clusters or internal referencs that may change.
Processing 4 A (IPv4 Address) Records
These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain. The www record is the most common one and will be used to identify your website address
- Host: bandcamp.com. = IP: [151.101.1.28] Valid Reachable (14.187ms)
- Host: bandcamp.com. = IP: [151.101.129.28] Valid Reachable (13.702ms)
- Host: bandcamp.com. = IP: [151.101.193.28] Valid Reachable (13.839ms)
- Host: bandcamp.com. = IP: [151.101.65.28] Valid Reachable (13.826ms)
Processing AAAA (IPv6 Address) Records
These records define the IP Addresse(s) of the servers responsible for hosting your webiste and other resouces on your domain
Processing Domain Public Records
- We have been unable to find the website IP from the zone
- Performed an additional out-of-zone lookup to find website host [151.101.1.28]
Domain Name WHOIS Information - bandcamp.com
- Domain Name BANDCAMP.COM
- Registry Domain ID 99054955_DOMAIN_COM-VRSN
- Registrar WHOIS Server whois.domaindiscover.com
- Registrar URL: http://www.domaindiscover.com
- Updated Date: 2017-12-26T05:46:30Z
- Creation Date: 2003-06-11T18:36:45Z
- Registry Expiry Date: 2023-01-02T04:59:59Z
- Registrar TierraNet Inc. d/b/a DomainDiscover
- Registrar IANA ID 86
- Registrar Abuse Contact Email This email address is being protected from spambots. You need JavaScript enabled to view it.
- Registrar Abuse Contact Phone 858-560-9416
- Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
- Name Server DNS3.EASYDNS.ORG
- Name Server DNS4.EASYDNS.INFO
- Name Server NS-321.AWSDNS-40.COM
- Name Server NS-958.AWSDNS-55.NET
- DNSSEC unsigned
- URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
Website Hosting WHOIS Information - 151.101.1.28
- NetRange 151.101.0.0 - 151.101.255.255
- CIDR 151.101.0.0/16
- NetHandle NET-151-101-0-0-1
- Parent RIPE-ERX-151 (NET-151-0-0-0-0)
- NetType Direct Assignment
- OriginAS
- Organization Fastly (SKYCA-3)
- RegDate 2016-02-01
- Updated 2016-02-01
- Ref: https://rdap.arin.net/registry/ip/151.101.0.0
- OrgName Fastly
- OrgId SKYCA-3
- Address PO Box 78266
- City San Francisco
- StateProv CA
- PostalCode 94107
- Country US
- RegDate 2011-09-16
- Updated 2020-04-09
- Ref: https://rdap.arin.net/registry/entity/SKYCA-3
- OrgTechHandle FRA19-ARIN
- OrgTechName Fastly RIR Administrator
- OrgTechPhone +1-415-404-9374
- OrgTechEmail rir-admin@fastly.com
- OrgTechRef: https://rdap.arin.net/registry/entity/FRA19-ARIN
- OrgAbuseHandle ABUSE4771-ARIN
- OrgAbuseName Abuse Account
- OrgAbusePhone +1-415-496-9353
- OrgAbuseEmail abuse@fastly.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE4771-ARIN
- OrgNOCHandle FNO19-ARIN
- OrgNOCName Fastly Network Operations
- OrgNOCPhone +1-415-404-9374
- OrgNOCEmail noc@fastly.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/FNO19-ARIN
Processing Website
Website Headers for www.bandcamp.com
We will obtain the headers from your website and parse them for validity
- Web Server is nginx
- Server header does not contain version information
- Request Response HTTP/1.1 301 Moved Permanently Moved Permanently
- SSL is available and enabled
/OU=Domain Control Validated/CN=*.bandcamp.com
- Locality
- Organisation
- Certificate Scope *.bandcamp.com
Certificate Issuer
- Country BE
- Organisation GlobalSign nv-sa
- Certificate Scope GlobalSign RSA DV SSL CA 2018
Certificate Validity
- Valid From 200319092614Z
- Valid To 210505201641Z
Certificate Ciphers
- SN RSA-SHA256
- LN sha256WithRSAEncryption
Certificate Extensions
- Alternative Hostnames DNS:*.bandcamp.com, DNS:bandcamp.com
- Key Usage TLS Web Server Authentication, TLS Web Client Authentication
- There was a redirect to http://bandcamp.com/
- There was a SECOND redirect https://bandcamp.com/
General
- allow Valid methods for a specified resource after a 405 : Missing
- location For Redirects specifies the target [https://bandcamp.com/]
- connection Control options for the current connection [keep-alive]
- x-powered-by Specifies Technology in use - Security Risk : Missing
- x-aspnet-version Specifies the ASP.net version - Security Risk : Missing
- accept-ranges To advertise its support of partial requests [bytes]
- link Used to express typed relationship with another resource : Missing
- upgrade HTTP/2 (The latest and faster version of HTTP is available : Missing
Security
- referrer-policy Modifies the algorithm used to populate the Referer Header : Missing
- x-xss-protection Prevents pages loading when XSS is detected : Missing
- feature-policy Allow or Deny the use of browser features : Missing
- p3p Platform for Privacy Preferences : Missing
- content-security-policy CSP Content Security Policy : Missing
- x-frame-options Can we open this response in an iframe : Missing
Cross Origin
- access-control-allow-origin Can we share the response with the given origin : Missing
- access-control-allow-credentials Tells Browsers whether to expose the response to frontend JavaScript : Missing
- access-control-expose-headers Indicates which headers can be exposed as part of the Response : Missing
- access-control-max-age Indicates how long the results of a preflight request can be stored : Missing
- access-control-allow-methods Methods allowed when accessing the resource in response to a preflight request : Missing
- access-control-allow-headers Indicates which headers can be used during the actual request : Missing
Content
- content-language The natural language or languages of the intended audience : Missing
- transfer-encoding The form of encoding used [chunked]
- content-length The length of the response body : Missing
- content-type The Media type of the Response Body : Missing
- date The date and time of generation [Sat, 18 Apr 2020 20:17:54 GMT]
- content-disposition An opportunity to raise a File Download dialogue box : Missing
- content-encoding The type of encoding/compression used on the Response : Missing
- content-location An alternate location for the returned data : Missing
- content-range Where in a full body message this partial message belongs : Missing
- etag An identifier for a specific version of a resource : Missing
- vary how to match future request headers : Missing
- x-content-type-options Types in Content-Type should NOT be changed : Missing
Cache
- cache-control Tells caches whether they may cache this object : Missing
- expires Gives the date/time after which the response is considered stale : Missing
- last-modified The last modified date for the requested object : Missing
- pragma Implementation-specific fields for caching : Missing
- x-cache-action From an Intermediate cache : Missing
- x-cache-hits Intermediate Cache Hits count [0]
- x-cache-age Intermediate Cache Content Age : Missing
- via Informs the client of proxies through which the response was sent [1.1 varnish]
- age The Age this page has been cached in a proxy [0]
- x-served-by The Cache that served this response [cache-lcy19226-LCY]
- x-cache Indicates if the cache served cached content [MISS]
- x-via-fastly Specific headers from Fastly : Missing
Strict Transport Security (HSTS) Policy
Cookies and Fragments
- set-cookie Cookie Data to store locally [BACKENDID=redpkhd-5; path=/; domain=.bandcamp.com]
Other
- x-backend-server Identifies the backend server providing this response : Missing
- x-robots-tag Search engine Robot Directive : Missing
- gen Used by some of the GEN Tools to verify zone ownership : Missing
- cf-cache-status Cloudflare Specific Header indicating cache status for this response : Missing
- x-aspnetmvc-version ASP MVC Version Number - Security Risk : Missing
Not Profiled
- x-timer [S1587241074.909507,VS0,VE122]
Robots.txt
- You have a robots.txt file and it appears to be valid
- Allow Entries (0) - Specific Allow
- Disallow Entries (26) - Specific Disallow
- Sitemap Entries (0) - Sitemaps
- Other Entries (9)
Processing Website Profile Data
Website Render for www.bandcamp.com
Technology Profile bandcamp.com
We will check for fingerprints of common website technologies
- Failed to succesfully profile the website, it is likely either custom or plain HTML.
MOZ Rank Profile http://bandcamp.com/
We will retrieve your Ranking Profile from Moz.com
- 489745 The number of external, equity links
- 523980 The number of internal and external equity and non-equity links
- 93 The Domain Authority (DA) ( 0->100 )
- 75 The Page Authority (PA) ( 0->100 )
- 7.5 The MozRank of the Domain ( 0->10 )
Google Safe Browsing http://bandcamp.com/
We will retrieve Safe Browsing Status from Google
PhishTank Lookup http://bandcamp.com/
We will check PhishTank to see if your site is listed
Alexa Rank Profile http://bandcamp.com/
We will retrieve your Ranking Profile from Alexa.com
Meta Profile http://bandcamp.com/
We will check the entire body for metadata
- description : Discover amazing music and directly support the artists who make it.
- msapplication-tilecolor : #603cba
- theme-color : #ffffff
- apple-mobile-web-app-capable : yes
- norton-safeweb-site-verification : ejd7gu5uojnhaq1f4mkwkx8rbydsxtne25pyxbyv24x7e2b-voeqw8wohh9j183bfyeq109vyl4vd396-wkx1gog2vv4g21x39voxpe75a96ahp98-nookkmva7n5t7a
- google-site-verification : eBKSmW-xBn9p7kJisv_YWdQC5oZgXeXWsvaqXkrSrq4
Processing Completed
- Performance Profile
- DNS Lookups : 0.26 seconds
- DNS Folding/Unfolding : 0.00 seconds
- DNS Nameserver Checks : 0.00 seconds
- DNS TXT Records : 0.00 seconds
- DNS MX Records : 0.75 seconds
- DNS CNAME : 0.00 seconds
- DNS Address : 0.10 seconds
- WHOIS Lookups : 0.32 seconds
- First CURL : 0.26 seconds
- Second CURL : 0.18 seconds
- SSL Lookup : 1.96 seconds
- Header Parsing : 0.00 seconds
- Robots.txt Parsing : 1.25 seconds
- Website Profile : 10.16 seconds
- Website MozData : 0.14 seconds
- Safe Browsing : 0.08 seconds
- PhishTank : 0.04 seconds
- Website Alexa : 0.41 seconds
- Website META : 0.76 seconds
The process is now completed and the results are shown above. The raw processing data is available HERE. Please take a moment to consider each test and its response. DNS, SMTP and HTTP are not simple protocols and it is way beyond the scope of this tool to suggest improvements, but you are welcome to request assistance via our Forum.