Website profiles · Technology insights · Alternatives

cloudflare.com Paid content Multilingual

Categories: Security & Privacy

Welcome to Cloudflare - Powering the next generation of applications

Visit website

Updated: 2026-09-03 15:14 Language: English (default) Access: Normal

Profile views 10 Outbound visits 8
Cloudflare Full homepage screenshot

Website Overview

A disclosed component version matches a published advisory. Its practical impact depends on the deployed configuration and whether the affected functionality is reachable. Identifiable technologies and additional version or configuration signals make the service easier to fingerprint, which may help targeted scanners narrow their checks.

Domain and Registration

Registered in 2009, this domain has about 17 years of history. That suggests continuity, although ownership and purpose may have changed. Transfer-protection status is present, helping reduce the risk of unauthorized domain transfers. The registrar is Cloudflare, Inc., a widely used domain service provider. The domain uses the common .com extension, which is not an independent safety signal.

DNS and Email

The lowest TTL is 52 seconds, supporting rapid record changes at the cost of more frequent lookups. Nameservers are provided by Cloudflare, indicating managed DNS hosting. MX records point to the Cloudflare Email Routing email service. DNSSEC is enabled, allowing validating resolvers to authenticate signed DNS data. CAA records restrict which certificate authorities are authorized to issue certificates.

TLS and Certificates

The public key uses EC with 256 bits. The server supplied a complete certificate chain. No organization name is present in the certificate; the available fields are consistent with domain validation. The certificate was issued within the Google Trust Services cloud or CDN ecosystem. The certificate's total validity is about 90 days, consistent with a short renewal cycle.

HTTP and Browser Security

No X-Powered-By header was found, reducing one common source of backend fingerprinting information. All six checked browser-security headers are present. Their effectiveness still depends on the policy values and application behavior. The cf-ray, x-served-by response header indicates a CDN or caching proxy in the delivery path. No obvious internal addresses or debug information were found in the headers. The Server header identifies cloudflare without an exact version.

Technology Stack Analysis

The public page identifies Astro 6.3.7, Cloudflare, with exact versions exposed for 1 technologies. These details can narrow vulnerability checks, although exposure alone is not a vulnerability. The advisory source OSV places Astro 6.3.7 in the affected range of GHSA-2pvr-wf23-7pc7, GHSA-4g3v-8h47-v7g6, GHSA-7pw4-f3q4-r2p2, GHSA-f48w-9m4c-m7f5, GHSA-jrpj-wcv7-9fh9. Verify the deployed version and relevant configuration before drawing conclusions about exploitability. Updating affected components should be a priority.

Search and Social Sharing

The Generator tag identifies Astro v6.3.7, making the publishing system easier to fingerprint. Twitter Card metadata is configured. JSON-LD includes Organization data, helping describe the organization as an entity. The page declares 10 language or regional alternatives using hreflang. The title has 35 characters, within a common display range.

Hosting and Email

DNSCloudflare
HostingFastly
EmailCloudflare Email Routing
Location United States flagUnited States 2606:4700::6810:7b60

Pages, Search and Sharing

Meta descriptionWelcome to Cloudflare - Powering the next generation of applications
Canonical URLhttps://www.cloudflare.com/
LanguageEnglish (default) · Multilingual
Twitter Cardsummary_large_image
All bots 1 allowed · 0 disallowed
  • Allow/
gptbot 1 allowed · 0 disallowed
  • Allow/
chatgpt-user 1 allowed · 0 disallowed
  • Allow/
google-extended 1 allowed · 0 disallowed
  • Allow/
anthropic-ai 1 allowed · 0 disallowed
  • Allow/
claude-web 1 allowed · 0 disallowed
  • Allow/
ccbot 1 allowed · 0 disallowed
  • Allow/
perplexitybot 1 allowed · 0 disallowed
  • Allow/
cohere-ai 1 allowed · 0 disallowed
  • Allow/

Registration details RDAP / WHOIS

RegistrarCloudflare, Inc.
Registered2009-02-17
Expires2033-02-17
Domain statusclient delete prohibited、client transfer prohibited、client update prohibited、server delete prohibited、server transfer prohibited、server update prohibited
Nameserversns3.cloudflare.com、ns4.cloudflare.com、ns5.cloudflare.com、ns6.cloudflare.com、ns7.cloudflare.com
DNSSECsigned

DNS records

TypeNameValueTTLPriority
Awww.cloudflare.com104.16.123.96133
Awww.cloudflare.com104.16.124.96133
AAAAwww.cloudflare.com2606:4700::6810:7b6052
AAAAwww.cloudflare.com2606:4700::6810:7c6052
MXcloudflare.commxa-canary.global.inbound.cf-emailsecurity.net16285
MXcloudflare.commxb-canary.global.inbound.cf-emailsecurity.net16285
MXcloudflare.commxa.global.inbound.cf-emailsecurity.net162810
MXcloudflare.commxb.global.inbound.cf-emailsecurity.net162810
NScloudflare.comns3.cloudflare.com81177
NScloudflare.comns4.cloudflare.com81177
NScloudflare.comns5.cloudflare.com81177
NScloudflare.comns6.cloudflare.com81177
NScloudflare.comns7.cloudflare.com81177
TXTcloudflare.comDirectFedAuthUrl=https://cloudflare-security.cloudflareaccess.com/cdn-cgi/access/sso/saml/dba6756ad312fc13c45f705cf7f5e87f4d658be016c41f950329aa4085b3abc1300
TXTcloudflare.comDirectFedAuthUrl=https://cloudflare-security.cloudflareaccess.com/cdn-cgi/access/sso/saml/ebec933773c69c93420d13e6776adb8c4a190f6281f9d132bcebd7dcb0967bdd300
TXTcloudflare.comMS=ms70274184300
TXTcloudflare.comZOOM_verify_7LFBvOO9SIigypFG2xRlMA300
TXTcloudflare.com_neqmkgaq1lq9it5s8qmetrhbnu121wb300
TXTcloudflare.com_saml-domain-challenge.2dc00405-79cd-457b-b288-a119c6f0c7b7.71996d53-d178-4ba9-bef4-7f7e46edab74.cloudflare.com=1c8736fd-84b2-4197-985f-3fb2852f2457300
TXTcloudflare.com_wkjc0fot0d7qrvrdt78bxkj2e2o67d2300
TXTcloudflare.comapple-domain-verification=DNnWJoArJobFJKhJ300
TXTcloudflare.comasv=894f6d1f9f83bcf44e4b1bc40bc1c4aa300
TXTcloudflare.comatlassian-domain-verification=WxxKyN9aLnjEsoOjUYI6T0bb5vcqmKzaIkC9Rx2QkNb751G3LL/cus8/ZDOgh8xB300
TXTcloudflare.comcanva-site-verification=oOyaVnHC-OiFoR1BPvetNA300
TXTcloudflare.comcisco-ci-domain-verification=27e926884619804ef987ae4aa1c4168f6b152ada84f4c8bfc74eb2bd2912ad72300
TXTcloudflare.comcreatopy-domain-verification=97d2ca50-9b6f-4a21-9bdb-fbb630e4cec7300
TXTcloudflare.comdatabank-domain-verification-hkehd2=fzgu4kmbZwMoW99zENgO4u8NL300
TXTcloudflare.comdocker-verification=c578e21c-34fb-4474-9b90-d55ee4cba10c300
TXTcloudflare.comdrift-domain-verification=f037808a26ae8b25bc13b1f1f2b4c3e0f78c03e67f24cefdd4ec520efa8e719f300
TXTcloudflare.comfacebook-domain-verification=h9mm6zopj6p2po54woa16m5bskm6oo300
TXTcloudflare.comgoogle-site-verification=C7thfNeXVahkVhniiqTI1iSVnElKR_kBBtnEHkeGDlo300
TXTcloudflare.comgoogle-site-verification=ZdlQZLBBAPkxeFTCM1rpiB_ibtGff_JF5KllNKwDR9I300
TXTcloudflare.comliveramp-site-verification=EhH1MqgwbndTWl1AN64hOTKz7hc1s80yUpchLbgpfY0300
TXTcloudflare.comlogmein-verification-code=b3433c86-3823-4808-8a7e-58042469f654300
TXTcloudflare.commiro-verification=bdd7dfa0a49adfb43ad6ddfaf797633246c07356300
TXTcloudflare.comonetrust-domain-verification=bd5cd08a1e9644799fdb98ed7d60c9cb300
TXTcloudflare.comstatus-page-domain-verification=r14frwljwbxs300
TXTcloudflare.comstripe-verification=5096d01ff2cf194285dd51cae18f24fa9c26dc928cebac3636d462b4c6925623300
TXTcloudflare.comstripe-verification=bf1a94e6b16ace2502a4a7fff574a25c8a45291054960c883c59be39d1788db9300
TXTcloudflare.comuber-domain-verification=58086039-150a-42a4-a4be-b4032921aa0f300
TXTcloudflare.comv=spf1 ip4:199.15.212.0/22 ip4:173.245.48.0/20 include:_spf.google.com include:spf1.mcsv.net include:spf.mandrillapp.com include:mail.zendesk.com include:stspg-customer.com include:_spf.salesforce.com -all300
CAAcloudflare.com0 iodef "mailto:[email protected]"300
CAAcloudflare.com0 issue "comodoca.com"300
CAAcloudflare.com0 issue "digicert.com; cansignhttpexchanges=yes"300
CAAcloudflare.com0 issue "letsencrypt.org"300
CAAcloudflare.com0 issue "pki.goog; cansignhttpexchanges=yes"300
CAAcloudflare.com0 issue "ssl.com"300
CAAcloudflare.com0 issuewild "comodoca.com"300
CAAcloudflare.com0 issuewild "digicert.com; cansignhttpexchanges=yes"300
CAAcloudflare.com0 issuewild "letsencrypt.org"300
CAAcloudflare.com0 issuewild "pki.goog; cansignhttpexchanges=yes"300
CAAcloudflare.com0 issuewild "ssl.com"300
DScloudflare.com2371 13 2 32996839a6d808afe3eb4a795a0e6a7a39a76fc52ff228b22b76f6d63826f2b986400
DMARC_dmarc.cloudflare.comv=DMARC1; p=reject; sp=reject; adkim=r; aspf=r; pct=100; rua=mailto:[email protected],mailto:[email protected]300

TLS and certificates

AssessmentNormal configuration
Supported protocolsTLSv1.2、TLSv1.3
Negotiated protocolTLSv1.3
Certificate subjectwww.cloudflare.com
IssuerGoogle Trust Services
Valid until2026-11-26T01:16 · Remaining when checked: 87 days
Verification detailsCertificate trust: Passed · Hostname match: Passed

HTTP response headers

HeaderValue
content-typetext/html; charset=utf-8
cache-controlmax-age=10
servercloudflare
strict-transport-securitymax-age=31536000; includeSubDomains
content-security-policydefault-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.cloudflareinsights.com https://static-staging.cloudflareinsights.com https://challenges.cloudflare.com https://*.onetrust.com https://cdn.cookielaw.org https://ot.www.cloudflare.com https://www.googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://adservice.google.com https://cdn.bizible.com https://js.adsrvr.org https://*.marketo.net https://platform.twitter.com https://static.ads-twitter.com https://scripts.demandbase.com https://tag.demandbase.com https://*.6sc.co https://*.qualified.com https://snap.licdn.com https://bat.bing.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.doubleclick.net https://www.googleadservices.com https://translate.googleapis.com https://cdn.bizible.com https://js.adsrvr.org https://*.marketo.net https://ads-twitter.com https://analytics.twitter.com https://*.twimg.com https://api.demandbase.com https://scripts.demandbase.com https://tag.demandbase.com https://tag-logger.demandbase.com https://api.company-target.com https://*.6sc.co https://epsilon.6sense.com https://*.qualified.com wss://*.qualified.com https://*.ads.linkedin.com https://www.linkedin.com https://bat.bing.com https:; frame-src https://*.adsrvr.org https://*.cloudflare.com https://*.videodelivery.net https://*.cloudflarestream.com https://www.googletagmanager.com https://*.qualified.com https://td.doubleclick.net https://bid.g.doubleclick.net https://9309168.fls.doubleclick.net https://9973066.fls.doubleclick.net https://s.company-target.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; worker-src 'self' blob:; child-src 'self' blob:; upgrade-insecure-requests
x-frame-optionsSAMEORIGIN
x-content-type-optionsnosniff
referrer-policystrict-origin-when-cross-origin
permissions-policygeolocation=(), camera=(), microphone=()
set-cookieRedacted

Identified technologies

Astro 6.3.7Cloudflare

Recent Updates

Related questions

More questions →

No related questions yet.

User reviews (0)