Ofo · Domain Security

Ofo Domain Security

Domain security

Domain security posture for Ofo, probed live across 1 host(s) and 0 registrable domain(s).

CompanyDefunctTransportationMobilityMicromobilityBike SharingSharing EconomyConsumerChina

Transport & Host Security

ofo.com
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

Source

Domain Security

ofo-domain-security.yml Raw ↑
generated: '2026-08-26'
method: probed
source: >-
  Direct TCP/TLS probe of 47.93.164.86 (ofo.com) plus DNS queries against 8.8.8.8 for TXT, MX,
  CAA, DS and DNSKEY on ofo.com.
scope: >-
  ofo.com only — the company's own former primary host. forgeglobal.com, which is currently the
  only URL in apis.yml common[], is a third-party secondary-market trading venue; its security
  posture is Forge Global's and is deliberately NOT probed or attributed to Ofo here.
pointer_emitted: false
pointer_note: >-
  No `DomainSecurity` (or `Security`) pointer is wired into apis.yml for this file. The scorer's
  `reg_security_posture` check awards points for the pointer alone, and Ofo publishes no security
  posture — every control below is absent and the web origin is offline. Wiring a pointer here
  would convert a verified absence into a scored presence.
hosts:
- host: ofo.com
  reachable: false
  ports:
    '80': closed
    '443': closed
  https: false
  tls_version: null
  hsts: null
  note: >-
    The A record resolves (47.93.164.86, Aliyun) and the registration is live through Alibaba
    Cloud to 2027-09-08, but the origin completes no TCP handshake on either web port, so TLS,
    HSTS and certificate posture cannot be observed at all — the web presence is off, not merely
    misconfigured.
dns:
  registrable_domain: ofo.com
  dnssec:
    enabled: false
    ds: []
    dnskey: []
  caa:
    present: false
    records: []
  spf:
    present: true
    valid: false
    records:
    - v=spf1 include:spf.163.com -all
    - v=spf1 include:spf.corp-email.com include:spfb.corp-email.com ~all
    note: >-
      TWO v=spf1 TXT records are published on the same name. RFC 7208 §4.5 makes that a
      permanent error — a receiver that finds more than one SPF record MUST return permerror,
      so in practice this domain has no usable SPF policy despite publishing two.
  dmarc:
    present: false
    record: null
  mx:
  - 5 hzmx01.mxmail.netease.com
  - 10 hzmx02.mxmail.netease.com
  other_txt:
  - MS=ms74974185
  note: >-
    Corporate mail is still delegated to NetEase business mail and the domain is still being
    renewed, so the registration is administered even though the website is gone. Mail
    authentication is nonetheless unusable: conflicting SPF records and no DMARC record at all.
x-evidence:
  fetched: '2026-08-26'
  probes:
  - url: https://ofo.com/
    status: 0
  - url: http://ofo.com/
    status: 0
  - url: https://www.ofo.com/
    status: 0

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ofo-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.