DNS report
quark.ammocan.dev
Complete DNS, mail, web and security analysis.
Cached report
Report created: 2026-09-19 17:54:11 EDT
17 h 54 min ago
Refresh report
DNS cache tools
If you have recently made DNS changes and they are not yet reflected in the report, you can try to flush the DNS cache of these public resolvers: The domain name will be copied to your clipboard automatically when clicking on a button
Category Status Test Details
WHOIS0.0 ms
Domain Status
Unable to retrieve WHOIS information for quark.ammocan.dev.
Retry, this time it might work!
Reason: empty whois/rdap response
PARENT0.0 ms
Domain NS records
No NS records found from ns1079.ui-dns.de.

dig: dig NS 'quark.ammocan.dev' @'8.8.8.8' +time=2 +tries=1 +noall +answer +authority +additional 2>/dev/null
TLD Parent Check
The parent server did not return any information for this TLD.
Your nameservers are listed
Mismatch between parent and domain NS.
DNS Parent sent Glue
0 of 0 nameservers sent GLUE.

The parent nameserver a.gtld-servers.net sent GLUE, meaning it sent your nameservers as well as the IPs of your nameservers.
Glue records are A records that are associated with NS records to provide "bootstrapping" information to the nameserver. (See RFC 1912 section 2.3)
Nameservers A records
Every nameserver listed has A records.
This is a must if you want to be found.
NS961.2 ms
NS records from your NameServers
NS records returned by the currently delegated nameservers are:

Oops! I could not get any nameservers from your nameservers.

Please verify that the nameservers listed at the parent are not lame and are configured properly.
Nameservers with no NS response:
    ingress.bot-hosting.cloud
Public Resolver
🌐 Cloudflare (GLOBAL)
1.1.1.1
🌐 Google DNS (GLOBAL)
8.8.8.8
🌐 Quad9 (GLOBAL)
9.9.9.9
OpenDNS (US)
208.67.222.222
CIRA Canadian Shield (CA)
149.112.121.10
CleanBrowsing (EU)
185.228.168.9
Quad9 (MX)
149.112.112.112
OpenDNS (ZA)
208.67.220.220
AdGuard DNS (EU)
94.140.14.14
ControlD (EU)
76.76.2.0
Yandex (RU)
77.88.8.8
114DNS (CN)
114.114.114.114
Mismatched NS records
Mismatch detected between parent and zone NS records.
Parent NS:

Zone NS:
ingress.bot-hosting.cloud

WARNING: One or more of your nameservers did not return any of your NS records.
DNS servers responded
The following NS did not respond to a basic query:
ingress.bot-hosting.cloud

❌ These nameservers did not respond to a standard non-recursive A query. This may indicate filtering, timeouts, or misconfiguration.
Name of nameservers are valid
All of the NS records that your nameservers report seem valid.
Multiple Nameservers
You only have 1 nameserver(s). RFC2182 recommends at least 2, ideally 3 or more.
Missing nameservers reported by parent
FAIL: The following nameservers are listed at your nameservers as nameservers for your domain, but are not listed at the parent nameservers (see RFC2181 5.4.1).
The missing NS records at the parent are:
    ingress.bot-hosting.cloud
You need to make sure that these nameservers are working. If they are not working correctly, you may experience problems.
Missing nameservers reported by your nameservers
All nameservers returned by the parent server are the same as the ones reported by your nameservers.
Domain CNAMEs
A CNAME record exists at the zone apex while other records are also present. This is invalid DNS configuration.
NSs CNAME check
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
Different subnets
All nameservers are on the same subnet (can be a risk).
Recursive Queries
ingress.bot-hosting.cloud → ❌ This DNS server allows recursion, which may pose a security risk (it responds to out-of-zone queries).
Same Glue
I do not consider this an error because no authoritative nameserver returned NS records for this domain.
NS Self-IP Consistency
Test skipped because no authoritative nameserver responded well enough to perform this check.
Glue for NS records
The delegated nameservers did not return NS records for this domain, so DNSprobe cannot verify child-side glue. This is treated as a pass because the main delegation problem has already been reported.
Nameservers are lame
OK. The nameservers listed at the parent are the delegated nameservers for this domain. No additional lame nameserver condition was detected beyond the response issue already reported above.
IPs of nameservers are public
Ok. Looks like the IP addresses of your nameservers are public.
This is a good thing because it will prevent DNS delays and other problems.
DNS servers allow TCP connection
Some authoritative name servers do not respond over TCP:
ingress.bot-hosting.cloud (178.105.112.237)
TCP support is important for large DNS replies (DNSSEC, long responses, truncation fallback).
Different autonomous systems
Only one nameserver found or unable to determine ASN for comparison.
Stealth NS records sent
The following name servers are configured in your zone but not reported by the parent (stealth NS):
    ingress.bot-hosting.cloud
Stealth name servers can cause inconsistent DNS answers and complicate troubleshooting. Make sure all authoritative NS are correctly published at the registry/parent level.
DNSSEC365.1 ms
Zone signed
DNSSEC: signedDelegation
RRSIG record present. The zone appears to be DNSSEC-signed.
DNSKEY records
quark.ammocan.dev. 60 IN CNAME ingress.bot-hosting.cloud.
DS record in parent
quark.ammocan.dev. 60 IN CNAME ingress.bot-hosting.cloud.
NSEC/NSEC3 record
No NSEC or NSEC3 record found when querying a non-existent subdomain.
This may indicate a misconfiguration or lack of proper DNSSEC denial-of-existence support.
Changing nameservers while DNSSEC is active
⚠️ Your domain is currently signed with DNSSEC.
Before changing your nameservers (NS), you must disable DNSSEC at your registrar. Otherwise, your domain may become unreachable due to missing or invalid signatures on the new servers.
SOA127.0 ms
SOA Record
The SOA (Start of Authority) record is:
    Primary nameserver:
    Hostmaster E-mail address:
    Serial #:
    Refresh:
    Retry:
    Expire:
    Default TTL:
NSs have same SOA serial
Inconsistent SOA serials returned by your nameservers:
SOA MNAME entry
is NOT listed at the parent level. This could cause issues with zone transfer or delegation.
SOA Serial
Your SOA serial number is: . This does not match the recommended YYYYMMDDnn format.
SOA REFRESH
Your SOA REFRESH interval is: . OK.
SOA RETRY
Your SOA RETRY value is: . OK.
SOA EXPIRE
Your SOA EXPIRE number is: . Looks OK.
SOA MINIMUM TTL
Your SOA MINIMUM TTL is: . This is fine
MX
...
MX Records
TXT0.1 ms
TXT Records
Host Type Value Size TTL
quark.ammocan.dev CNAME "-" 0 60
DMARC81.9 ms
DMARC Record
No valid DMARC record was found at _dmarc.quark.ammocan.dev.
MTA-STS / TLS-RPT230.9 ms
Mail TLS security
TXT _mta-stsNot found
Policy URLhttps://mta-sts.quark.ammocan.dev/.well-known/mta-sts.txt (HTTP 0, policy missing)
Modenot set
Authorized MXnot set
max_agenot set
Policy fileNo valid MTA-STS policy file was fetched.
TXT _smtp._tlsNot found
MTA-STS score 0/5
Recommendations:
  • Publish an _mta-sts TXT record containing v=STSv1; id=. Change id whenever the HTTPS policy changes.
  • Publish the MTA-STS policy at https://mta-sts.quark.ammocan.dev/.well-known/mta-sts.txt with version: STSv1, mode, mx, and max_age.
  • Use mode: enforce to prevent delivery to MX hosts that do not satisfy the TLS policy.
  • Add at least one mx: line matching the domain's legitimate MX hosts.
  • Set max_age to at least 604800 seconds once the policy is stable.
  • Publish an _smtp._tls TXT record with v=TLSRPTv1; rua=mailto:tlsrpt@yourdomain to receive TLS reports.
DKIM
...
DKIM Records Detected
BIMI103.7 ms
BIMI Record
No BIMI record found at: default._bimi.quark.ammocan.dev.
SSL
...
SSL Certificate Summary
CAA
...
CAA Records
HSTS
...
HSTS
HTTPS
...
HTTPS
HTTPS (DNS)
...
HTTPS DNS record
WWW
...
A Record
AXFR
(Zone Transfer)335.7 ms
AXFR status for the zone
AXFR is refused by the authoritative nameservers for quark.ammocan.dev.
Nameservers tested:
    ingress.bot-hosting.cloud
Security note
Zone transfers (AXFR) should be disabled in production unless explicitly required and restricted.
Leaving AXFR open allows anyone to enumerate your entire DNS zone (subdomains, MX, TXT, internal hosts, etc.).
PORTS
...
Open ports detected (178.105.112.237)
REPUTATION
...
IP in blacklists (178.105.112.237)
DNS found
...
Test Details
Website Preview0.0 ms
Snapshot is generated through DNSprobe's rendering proxy and may be served from a short cache.
Security Headers643.9 ms
Score: 11/100 (F)
Failing, very weak or absent security headers

HeaderValue
HTTP/2
HTTP/2 206
HTTP version reported by the server.
set-cookie
None
Session cookies should include the Secure attribute to ensure they are never sent over unencrypted connections.
expires
None
Legacy caching header. Prefer Cache-Control.
cache-control
None
Controls caching. For sensitive pages consider 'no-store'.
pragma
None
Legacy HTTP/1.0 directive. Prefer Cache-Control.
content-type
text/html; charset=utf-8
Declares MIME type; pair with X-Content-Type-Options: nosniff.
content-encoding
None
Compression used for the response (gzip, br…).
vary
None
Tells caches which request headers affect the response.
date
Sat, 19 Sep 2026 21:54:15 GMT
Origin date of the response.
age
None
Indicates how long the response has been cached.
x-powered-by
Not defined
May reveal framework/version. Removing lowers fingerprinting.
strict-transport-security
Not defined
Enforces HTTPS for a period, strengthening TLS.
Enable HTTP Strict Transport Security (HSTS) to enforce secure connections.
x-xss-protection
Not defined
Deprecated. X-XSS-Protection sets the configuration for the legacy XSS Auditor in older browsers.
The recommended value used to be "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead.
x-content-type-options
Not defined
Stops MIME sniffing. Only valid value: 'nosniff'.
Use X-Content-Type-Options: nosniff.
x-permitted-cross-domain-policies
Not defined
Controls Flash/Adobe cross-domain policies. Use 'none'.
Prefer X-Permitted-Cross-Domain-Policies: none.
referrer-policy
Not defined
Controls referrer information sent on navigation.
Recommended: strict-origin-when-cross-origin.
permissions-policy
Not defined
Restricts powerful features (camera, mic, geolocation…).
Add a Permissions-Policy to restrict powerful features.
expect-ct
Not defined
Deprecated control, should be removed if present.
x-frame-options
Not defined
Protects against clickjacking. Prefer CSP frame-ancestors today.
Add frame-ancestors (CSP) or X-Frame-Options.
content-security-policy
Not defined
CSP limits content sources to mitigate XSS.
No CSP detected; add one to mitigate XSS.
cross-origin-embedder-policy
Not defined
COEP is part of cross-origin isolation (with COOP).
cross-origin-embedder-policy-report-only
Not defined
COEP in report-only mode (not enforced).
cross-origin-opener-policy
Not defined
COOP isolates browsing context groups when set to same-origin.
cross-origin-opener-policy-report-only
Not defined
COOP in report-only mode (not enforced).
cross-origin-resource-policy
Not defined
CORP restricts who can load this resource.
access-control-allow-origin
Not defined
CORS: which origins are allowed to read this response.
access-control-allow-methods
Not defined
CORS: which methods are allowed.
access-control-allow-headers
Not defined
CORS: which request headers are allowed.
alt-svc
h3=":443"; ma=2592000
Advertises alternative services (e.g., HTTP/3 via QUIC).
Other detected headers
Additional headers returned by the server. Shown for information only and not included in the score.
HeaderValue
accept-rangesbytes
content-rangebytes 0-0/7992
etag"9214b2ab21b9ba1ad24bc6e8eaaccac6"
last-modifiedFri, 11 Sep 2026 17:36:56 GMT
serveruvicorn
via1.1 Caddy
content-length1
Recommended starter configuration (.htaccess)
Starter configuration to copy and adapt. CSP, CORS and cookie rewriting are intentionally commented because they can break some sites if enabled blindly.


#BEGIN SECURITY HEADERS

# -------------------------------------------------------
# Safe baseline
# -------------------------------------------------------
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTPS} !=on
  RewriteCond %{HTTP:X-Forwarded-Proto} !https [NC]
  RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
</IfModule>

Options -Indexes

<IfModule mod_headers.c>
  # Reduce fingerprinting
  # The Server header usually cannot be removed from .htaccess; configure it at the web server level if needed.
  Header always unset X-Powered-By
  Header always unset X-Redirect-By

  # TLS / transport security (only when HTTPS)
  Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" env=HTTPS

  # MIME sniffing protection
  Header always set X-Content-Type-Options "nosniff"

  # Referrer policy
  Header always set Referrer-Policy "strict-origin-when-cross-origin"

  # Adobe cross-domain policy
  Header always set X-Permitted-Cross-Domain-Policies "none"

  # Clickjacking protection (consistent with CSP frame-ancestors 'self')
  Header always set X-Frame-Options "SAMEORIGIN"

  # Cross-Origin isolation headers (sane defaults)
  Header always set Cross-Origin-Opener-Policy "same-origin"
  Header always set Cross-Origin-Resource-Policy "same-origin"
  # COEP is powerful but can break third-party embeds/resources if not CORP/CORS-enabled.
  # Header always set Cross-Origin-Embedder-Policy "require-corp"

  # Deprecated header; modern browsers rely on CSP instead, but some scanners still like to see it.
  Header always set X-XSS-Protection "0"

  # Permissions-Policy (balanced: blocks sensitive features, allows reasonable ones on self)
  Header always set Permissions-Policy "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=(), display-capture=(), autoplay=(self), encrypted-media=(self), fullscreen=(self), picture-in-picture=(self), clipboard-write=(self), publickey-credentials-get=(self)"

  # Vary (keep small; don’t add Referer/User-Agent unless you truly vary by them)
  Header always merge Vary "Accept-Encoding"
</IfModule>

# -------------------------------------------------------
# Cache-Control (HTML pages)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # Apply to HTML responses (works for WordPress permalinks too). Requires Apache 2.4+ expressions.
  # If you do not use a page cache (LiteSpeed Cache, cache plugins, etc.), you can uncomment the line below. Keep it commented if a page cache is active.
  # Header always set Cache-Control "private, no-cache, must-revalidate" "expr=%{CONTENT_TYPE} =~ m#^text/html#"
  # Header always unset Pragma "expr=%{CONTENT_TYPE} =~ m#^text/html#"
  # Header always unset Expires "expr=%{CONTENT_TYPE} =~ m#^text/html#"
</IfModule>

# -------------------------------------------------------
# CSP - Content Security Policy (minimal safe baseline)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # (Keeps your current intent; strengthen later with default-src/script-src/etc.)
  # Adjust img-src, script-src, style-src, font-src, connect-src as needed (e.g., add trusted CDNs).
  # Header always set Content-Security-Policy "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; img-src 'self' data: https:; script-src 'self'; style-src 'self'; font-src 'self' data:; connect-src 'self'; form-action 'self'; upgrade-insecure-requests"
</IfModule>

# -------------------------------------------------------
# CORS - Cross-Origin Ressource Sharing (optional; keep commented unless needed)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # IMPORTANT:
  # - Do NOT enable global CORS unless you have a real API need.
  # If you need CORS, uncomment and set a fixed allowlist.
  # SetEnvIf Origin "^https?://(quark\.ammocan\.dev|www\.quark\.ammocan\.dev)(:\d{1,5})?$" CORS_ALLOW_ORIGIN=$0
  # Header always set Access-Control-Allow-Origin "%{CORS_ALLOW_ORIGIN}e" env=CORS_ALLOW_ORIGIN
  # Header always merge Vary "Origin" env=CORS_ALLOW_ORIGIN
  # Header always set Access-Control-Allow-Methods "GET, POST, OPTIONS" env=CORS_ALLOW_ORIGIN
  # Header always set Access-Control-Allow-Headers "Content-Type, Authorization" env=CORS_ALLOW_ORIGIN
  # Header always set Access-Control-Max-Age "86400" env=CORS_ALLOW_ORIGIN
</IfModule>

# -------------------------------------------------------
# Cookies hardening (optional)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # Apache only: uses Header edit/edit* to append Secure/HttpOnly/SameSite when missing. Not valid / not supported reliably on LiteSpeed/OpenLiteSpeed.
  # Header always edit* Set-Cookie "(?i)^((?:(?!;\s*Secure).)+)$" "$1; Secure" env=HTTPS
  # Header always edit* Set-Cookie "(?i)^((?:(?!;\s*HttpOnly).)+)$" "$1; HttpOnly"
  # Header always edit* Set-Cookie "(?i)^((?:(?!;\s*SameSite=).)+)$" "$1; SameSite=Lax"
</IfModule>

# -------------------------------------------------------
# Reporting headers (optional)
# -------------------------------------------------------
<IfModule mod_headers.c>
  # Header always set Reporting-Endpoints "default=\"https://quark.ammocan.dev/reporting\""
  # Header always set Cross-Origin-Opener-Policy-Report-Only "same-origin"
  # Header always set Cross-Origin-Embedder-Policy-Report-Only "require-corp"
</IfModule>

#END SECURITY HEADERS
WHOIS
Unable to retrieve registration data for quark.ammocan.dev.

You like this tool?

Buy Me A Coffee

Processed in 0.01 seconds.
Made with with PHP and a bit of JS.
Lines of code: 20,351

⚙️ Configuration
(Check / Uncheck All)