Ofo · Domain Security
Ofo Domain Security
Domain security
Domain security posture for Ofo, probed live across 1 host(s) and 0 registrable domain(s).
CompanyDefunctTransportationMobilityMicromobilityBike SharingSharing EconomyConsumerChina
Transport & Host Security
ofo.com
HTTPS: no
· HSTS: no
Domain (DNS/Email) Security
Source
Domain Security
generated: '2026-08-26'
method: probed
source: >-
Direct TCP/TLS probe of 47.93.164.86 (ofo.com) plus DNS queries against 8.8.8.8 for TXT, MX,
CAA, DS and DNSKEY on ofo.com.
scope: >-
ofo.com only — the company's own former primary host. forgeglobal.com, which is currently the
only URL in apis.yml common[], is a third-party secondary-market trading venue; its security
posture is Forge Global's and is deliberately NOT probed or attributed to Ofo here.
pointer_emitted: false
pointer_note: >-
No `DomainSecurity` (or `Security`) pointer is wired into apis.yml for this file. The scorer's
`reg_security_posture` check awards points for the pointer alone, and Ofo publishes no security
posture — every control below is absent and the web origin is offline. Wiring a pointer here
would convert a verified absence into a scored presence.
hosts:
- host: ofo.com
reachable: false
ports:
'80': closed
'443': closed
https: false
tls_version: null
hsts: null
note: >-
The A record resolves (47.93.164.86, Aliyun) and the registration is live through Alibaba
Cloud to 2027-09-08, but the origin completes no TCP handshake on either web port, so TLS,
HSTS and certificate posture cannot be observed at all — the web presence is off, not merely
misconfigured.
dns:
registrable_domain: ofo.com
dnssec:
enabled: false
ds: []
dnskey: []
caa:
present: false
records: []
spf:
present: true
valid: false
records:
- v=spf1 include:spf.163.com -all
- v=spf1 include:spf.corp-email.com include:spfb.corp-email.com ~all
note: >-
TWO v=spf1 TXT records are published on the same name. RFC 7208 §4.5 makes that a
permanent error — a receiver that finds more than one SPF record MUST return permerror,
so in practice this domain has no usable SPF policy despite publishing two.
dmarc:
present: false
record: null
mx:
- 5 hzmx01.mxmail.netease.com
- 10 hzmx02.mxmail.netease.com
other_txt:
- MS=ms74974185
note: >-
Corporate mail is still delegated to NetEase business mail and the domain is still being
renewed, so the registration is administered even though the website is gone. Mail
authentication is nonetheless unusable: conflicting SPF records and no DMARC record at all.
x-evidence:
fetched: '2026-08-26'
probes:
- url: https://ofo.com/
status: 0
- url: http://ofo.com/
status: 0
- url: https://www.ofo.com/
status: 0
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ofo-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.