Skip to content
RequestGuard Domain Intelligence
Pricing

Domain intelligence

Security Report for tiktokv.com

A closer look at this domain’s security, infrastructure, and public records. Findings first, with the evidence behind every result.

Explore the report
Website security grade F 55/100

Website Security

HTTPS, browser protections, DNS controls and known threats

Grade F #49 of 74

Important protections are missing

Several public security settings need attention. Start with the highest-value fixes below.

F55/100

Secure connection

Strong

40/40

Browser protections

Weak

0/30

Domain protection

Weak

0/15

Known threats

Strong

15/15

Fix these first

  1. 1

    Content security policy

    0/10

    To earn 10/10, send an enforced Content-Security-Policy header with script-src or default-src limited to 'self' and exact required hosts. Start in report-only mode, fix violations, then enforce the policy; report-only alone earns partial points.

  2. 2

    DNSSEC

    0/8

    To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.

  3. 3

    Certificate authority restriction

    0/7

    To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.

Strongest results

  • HTTPS response

    15/15

    HTTPS returned status 404.

  • Valid TLS certificate

    10/10

    The TLS certificate is valid for this domain.

  • Known malware reports

    6/6

    No active malware-distribution URL was reported.

All 15 security checks

Every result is shown, with what it means and how to fix it.

Working

HTTPS response

HTTPS returned status 404.

15/15
Working

Valid TLS certificate

The TLS certificate is valid for this domain.

10/10
Working

HTTP redirects to HTTPS

HTTP redirects to HTTPS.

5/5
Working

Modern TLS

TLSv1.3 was negotiated.

5/5
Working

Strict transport security

Strict-Transport-Security covers at least 180 days.

5/5
Needs attention

Content security policy

Content-Security-Policy is missing.

To earn 10/10, send an enforced Content-Security-Policy header with script-src or default-src limited to 'self' and exact required hosts. Start in report-only mode, fix violations, then enforce the policy; report-only alone earns partial points.

0/10
Needs attention

Frame protection

No enforced frame restriction was found.

To earn 5/5, add frame-ancestors 'none' (or 'self' if same-site framing is required) to the enforced Content-Security-Policy. X-Frame-Options: DENY or SAMEORIGIN is also accepted.

0/5
Needs attention

Content type protection

X-Content-Type-Options: nosniff is missing.

To earn 5/5, send X-Content-Type-Options: nosniff on the homepage response.

0/5
Needs attention

Referrer policy

Referrer-Policy is missing.

To earn 5/5, send Referrer-Policy: strict-origin-when-cross-origin. no-referrer, same-origin, and strict-origin also receive full points.

0/5
Needs attention

Browser permissions policy

Permissions-Policy is missing.

To earn 5/5, disable all three tested capabilities: Permissions-Policy: camera=(), microphone=(), geolocation=(). Add separate directives for capabilities the site intentionally allows.

0/5
Needs attention

DNSSEC

DNSSEC validation data was not found.

To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.

0/8
Needs attention

Certificate authority restriction

No CAA record was found.

To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.

0/7
Working

Known malware reports

No active malware-distribution URL was reported.

6/6
Working

Threat-blocking DNS

3 threat-protection resolvers returned the domain.

5/5
Working

Domain blocklists

The domain did not match the checked domain blocklists.

4/4

This dated automated check does not verify the business, its content, or every page. The score describes the configuration observed during this scan.

Badges and embed code
Embed code
<a href="https://requestguard.com/domain/tiktokv.com/">
  <img src="https://requestguard.com/domain/tiktokv.com/badges/security.svg" alt="Website security grade for tiktokv.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/tiktokv.com/#infrastructure">
  <img src="https://requestguard.com/domain/tiktokv.com/badges/location.svg" alt="Network location for tiktokv.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/tiktokv.com/">
  <img src="https://requestguard.com/domain/tiktokv.com/badges/trust.svg" alt="Trust badge for tiktokv.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/tiktokv.com/#whois">
  <img src="https://requestguard.com/domain/tiktokv.com/badges/domain-rating.svg" alt="Domain Rating for tiktokv.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Use these results through the API

API requests require a workspace key and a plan with Lookups access.

The hosted badge updates after a manual scan. A downloaded badge stays static and avoids contacting RequestGuard on page views.

Search visibility

Homepage signals that can affect crawling and indexing

Obstacles found

Obstacles found

The crawler found technical obstacles that may prevent access or indexing. Start with the flagged checks below.

6 homepage checks · Unscored

Observed request

https://tiktokv.com/

Obstacle

Automated crawler access

The homepage returned HTTP 404, which says that the page is missing.

Serve the intended homepage with HTTP 200, then request validation in Google Search Console.

Clear

Indexing directives

No Google noindex directive was found in the response headers or sampled HTML.

Clear

robots.txt homepage rule

robots.txt returned HTTP 404. Google treats this as no crawl restrictions because the response is not 429.

Review

Canonical URL

No HTML canonical link was found. This is not a block, but it leaves the preferred URL less explicit.

Add one absolute, self-referencing canonical URL to the homepage.

Obstacle

Search-readable HTML

The sampled homepage response used HTTP 404, so indexable page content was not available.

Return the public homepage content with HTTP 200.

Review

Sitemap discovery

No XML sitemap declaration or conventional /sitemap.xml response was found. A sitemap is optional, but it helps discovery for new sites.

Publish an XML sitemap and declare it in robots.txt or submit it in Google Search Console.

This is not a Google index lookup. RequestGuard tests public signals with an identified automated crawler. Only URL Inspection for a verified Google Search Console property can confirm Google's last crawl, selected canonical, and indexing decision.

Open Google's URL Inspection guide

Cached result

Public exposure

Sensitive files and public administrative interfaces

Unscored

Not checked—run a website scan.

Checks 100 common paths and up to 50 technology-specific paths. Opening this report does not start exposure checks.

These are bounded, unauthenticated crawler observations, not a penetration test. A public login is not automatically a vulnerability. Secret values are discarded. Findings do not affect your security score.

Server Infrastructure

Resolved addresses, networks, and hosting providers

Loading infrastructure evidence

DNS Records

A, AAAA, MX, and resolving certificate hostnames, with other record types on demand

Loading DNS records

Email & DNS Security

MX, SPF, DMARC, DNSSEC, and CAA posture

Loading email and DNS posture

WHOIS & Registrar

Registration details via RDAP

RDAP

Registered 9.0 years ago

Registration history and published ownership records. Domain age and Domain Rating are context, not a security verdict.

Registrar

Gandi SAS

Abuse: abuse@gandi.net

Registration dates

Domain age

9.0 years

Created

Sep 20, 2017

Updated

Aug 20, 2026

Expires

Sep 20, 2027

Registrant

Privacy protected

Identity is hidden by a privacy service — standard practice under GDPR and similar laws, not on its own a sign of anything suspicious.

Name Redacted for Privacy
Organization TIKTOK LTD
Email b41bc001f0e976322e09f1964b14fa5b-20984426@contact.gandi.net
Location KY KY

Some of the data in this object has been removed.

Domain status

Registry status codes — green means the owner locked out unauthorized changes

Transfer locked

Checked

Reputation & DNS filtering

Resolver behavior, domain datasets, and server-IP evidence

No threat match

Resolver summary

No match found in 3 checked threat-protection resolvers.

Checked . No-match results apply only to the sources that returned comparable evidence.

Resolver filtering records provider behavior. It does not by itself prove that a domain is malicious.

Resolver matrix

Five public filtering policies compared with neutral DNS

5 comparable · 0 unavailable

Threat protection

Malware and phishing policy

Ads & tracking

Mixed privacy and security policy

Family / content

Content and security policy

Reputation datasets

URL and domain-list evidence, separate from resolver policy

0 of 1 active matches
URLhaus No match

Reported malware-distribution URLs

SURBL (via URLhaus) Unavailable

URLhaus metadata; this is not a direct SURBL query

Spamhaus DBL (via URLhaus) Unavailable

URLhaus metadata; this is not a direct Spamhaus DBL query

Server-IP DNSBL checks & threat feeds NL 2.21.22.24

DNSBL and network-feed matches do not determine the domain verdict. Shared hosting, reverse proxies, and CDNs can put unrelated domains on the same address.

0 of 4 matched, 6 unavailable

Barracuda

b.barracudacentral.org

No match

SpamCop

bl.spamcop.net

No match

UCEPROTECT L1

dnsbl-1.uceprotect.net

No match

DroneBL

dnsbl.dronebl.org

No match

X4B VPN ranges

raw.githubusercontent.com

Feed file is unavailable

Unavailable

X4B datacenter ranges

raw.githubusercontent.com

Feed file is unavailable

Unavailable

Tor exit nodes

check.torproject.org

Feed file is unavailable

Unavailable

Team Cymru fullbogons IPv4

team-cymru.org

Feed file is unavailable

Unavailable

Spamhaus DROP IPv4

www.spamhaus.org

Feed file is unavailable

Unavailable

Feodo Tracker C2

feodotracker.abuse.ch

Feed file is unavailable

Unavailable

NextDNS and other custom profiles are not tested because their result depends on enabled lists, security settings, and parental controls. Check the provider log for the exact rule.

Cached result