Domain intelligence
Security Report forchatgptlogin.com
A closer look at this domain’s security, infrastructure, and public records.
Website Security
HTTPS, browser protections, DNS controls and known threats
Several protections need work
RequestGuard found configuration gaps that the website owner should fix.
Secure connection
Weak35/40
Browser protections
Weak19/30
Domain protection
Weak0/15
Known threats
Strong15/15
Fix these first
- 1
DNSSEC
0/8To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.
- 2
Certificate authority restriction
0/7To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.
- 3
Content security policy
4/10To earn 10/10, add an effective script restriction, for example: Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'. Add only the exact external hosts the site needs.
Strongest results
-
HTTPS response
15/15HTTPS returned status 200.
-
Valid TLS certificate
10/10The TLS certificate is valid for this domain.
-
Known malware reports
6/6No active malware-distribution URL was reported.
All 15 security checks
Every result is shown, with what it means and how to fix it.
HTTPS response
HTTPS returned status 200.
Valid TLS certificate
The TLS certificate is valid for this domain.
HTTP redirects to HTTPS
HTTP does not redirect to HTTPS.
To earn 5/5, return a 301 or 308 from every HTTP URL to the same path and query on HTTPS.
Modern TLS
TLSv1.3 was negotiated.
Strict transport security
Strict-Transport-Security covers at least 180 days.
Content security policy
Content-Security-Policy is enforced but does not restrict script sources.
To earn 10/10, add an effective script restriction, for example: Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'. Add only the exact external hosts the site needs.
Frame protection
The response limits which sites may frame it.
Content type protection
Content type sniffing is disabled.
Referrer policy
Referrer-Policy uses strict-origin-when-cross-origin.
Browser permissions policy
Permissions-Policy is missing.
To earn 5/5, disable all three tested capabilities: Permissions-Policy: camera=(), microphone=(), geolocation=(). Add separate directives for capabilities the site intentionally allows.
DNSSEC
DNSSEC validation data was not found.
To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.
Certificate authority restriction
No CAA record was found.
To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.
Known malware reports
No active malware-distribution URL was reported.
Threat-blocking DNS
2 threat-protection resolvers returned the domain.
Domain blocklists
The domain did not match the checked domain blocklists.
This dated automated check does not verify the business, its content, or every page. The score describes the configuration observed during this scan.
Badges and embed code
Embed code
<a href="https://requestguard.com/domain/chatgptlogin.com/">
<img src="https://requestguard.com/domain/chatgptlogin.com/badges/security.svg" alt="Website security grade for chatgptlogin.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> Embed code
<a href="https://requestguard.com/domain/chatgptlogin.com/#infrastructure">
<img src="https://requestguard.com/domain/chatgptlogin.com/badges/location.svg" alt="Network location for chatgptlogin.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> Embed code
<a href="https://requestguard.com/domain/chatgptlogin.com/">
<img src="https://requestguard.com/domain/chatgptlogin.com/badges/trust.svg" alt="Trust badge for chatgptlogin.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> Embed code
<a href="https://requestguard.com/domain/chatgptlogin.com/#whois">
<img src="https://requestguard.com/domain/chatgptlogin.com/badges/domain-rating.svg" alt="Domain Rating for chatgptlogin.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> API requests require a workspace key and a plan with Lookups access.
The hosted badge updates after a manual scan. A downloaded badge stays static and avoids contacting RequestGuard on page views.
Search visibility
Homepage signals that can affect crawling and indexing
Needs review
Some homepage signals need a closer look. Review the recommendations below.
6 homepage checks · Unscored
Observed request
Automated crawler access
The identified crawler received HTTP 200 for the homepage.
Indexing directives
No Google noindex directive was found in the response headers or sampled HTML.
robots.txt homepage rule
No robots.txt rule blocking Googlebot from the homepage was found.
Canonical URL
The canonical URL stays on chatgptlogin.com and matches the homepage path.
Search-readable HTML
The initial HTML contains a title and visible page content.
Sitemap discovery
The conventional /sitemap.xml location could not be checked.
This is not a Google index lookup. RequestGuard tests public signals with an identified automated crawler. Only URL Inspection for a verified Google Search Console property can confirm Google's last crawl, selected canonical, and indexing decision.
Open Google's URL Inspection guideCached result
Public exposure
Sensitive files and public administrative interfaces
Not checked—run a website scan.
Checks 100 common paths and up to 50 technology-specific paths. Opening this report does not start exposure checks.
These are bounded, unauthenticated crawler observations, not a penetration test. A public login is not automatically a vulnerability. Secret values are discarded. Findings do not affect your security score.
Server Infrastructure
Resolved addresses, networks, and hosting providers
DNS Records
A, AAAA, MX, and resolving certificate hostnames, with other record types on demand
Email & DNS Security
MX, SPF, DMARC, DNSSEC, and CAA posture
WHOIS & Registrar
Registration details via RDAP
Registered 95 days ago
Registration history and published ownership records. Domain age and Domain Rating are context, not a security verdict.
Registrar
Registration dates
Domain age
95 days
Created
Jun 8, 2026
Updated
Jun 8, 2026
Expires
Jun 8, 2027
Registrant
Domain status
Registry status codes — green means the owner locked out unauthorized changes
Checked
Reputation & DNS Filtering
Resolver filtering, domain datasets, and server-IP DNSBL evidence