Skip to main content

gravitec.net

Jan 18th 2028 08:22 PM

PDR Ltd. d/b/a PublicDomainRegistry.com

unsigned

Yes

May 19th 2026 07:33 AM

Gravitec.net appears to be a domain with unknown purpose, but it's using Cloudflare's nameservers, suggesting a potential security feature. It was registered in 2016 and has an unsigned DNSSEC status, which may pose a security risk.

Data on this page is collected by cside's crawler, which monitors third-party scripts across the public web.

Copy Summary
Copy Link
Helpful
Not Helpful
Rarely seen
Vendor

Gravitec

Category: marketing

Description

Gravitec is a web and mobile push-notification service (founded 2014, Kyiv) that lets websites collect push subscribers and send automated push campaigns, drip sequences, and RSS-to-push notifications.

AI Review

The scripts operated by gravitec.net facilitate web push notifications and integrate with Firebase, utilizing service workers to manage user interactions and permissions. They employ dynamic loading patterns, indicative of SDK behavior, and track user activities through IndexedDB, raising potential privacy concerns as they monitor user behaviors throughout sessions. While these functionalities are designed to enhance user engagement — including notifications related to transactions — the broad data collection scope can intersect with sensitive data contexts during user interactions on payment pages. This raises questions about data minimization and the potential for unintentional data leakage given the persistent tracking of user sessions. The absence of alerts in the past week indicates that the script operates within expected parameters without any significant security incidents noted against it. However, the reliance on external APIs for notifications and the nature of background behavior tracking present ongoing risks, particularly if the collected data is not adequately restricted to engagement metrics exclusive of sensitive input. Thus, while the vendor claims that their services enhance user experience, the inherent tradeoff with privacy requires careful oversight to ensure compliance with data protection standards and responsively address any unintended data exposures.

Script hostnames

gravitec.net
WHOIS Information
Registrar PDR Ltd. d/b/a PublicDomainRegistry.com
Registration: January 18th, 2016
Expires: January 18th, 2028
Updated: May 19th, 2026
Nameservers
annalise.ns.cloudflare.com. 108.162.194.234
roan.ns.cloudflare.com. 172.64.33.226
Meta Tags

No meta tags found.

SSL Certificate
Status:

Enabled

Expires: December 5th, 2026
Issuer:

gravitec.net is one of thousands of third-party scripts on the web.

Most sites run dozens of third-party scripts and can't say what each one does. cside monitors every script on your site and catches the ones that change or turn malicious.

DNS Records
Hostname Type TTL Priority Content
gravitec.net NS 86400
annalise.ns.cloudflare.com.
gravitec.net NS 86400
roan.ns.cloudflare.com.
gravitec.net A 600
52.29.134.73
gravitec.net MX 3600 1
aspmx.l.google.com.
gravitec.net MX 3600 10
alt3.aspmx.l.google.com.
gravitec.net MX 3600 10
alt4.aspmx.l.google.com.
gravitec.net MX 3600 5
alt1.aspmx.l.google.com.
gravitec.net MX 3600 5
alt2.aspmx.l.google.com.
gravitec.net TXT 3600
"MS=ms62967122"
gravitec.net TXT 3600
"_globalsign-domain-verification=Gm_O1W5norhpv02qU6V_3P5EpjXa2XBXwhbu8OVV9M"
gravitec.net TXT 3600
"_globalsign-domain-verification=HTX4lvTQOilczw9WGOzMRQHMJKjcNJCcldxQ57uimF"
gravitec.net TXT 3600
"_globalsign-domain-verification=q-EjchkKAi98bfw7VqMeAD9Un9bPZoADSEBphGea5d"
gravitec.net TXT 3600
"v=spf1 ip4:168.245.11.227 a mx include:spf.protection.outlook.com include:_spf.google.com ~all"
gravitec.net SOA 1800
annalise.ns.cloudflare.com. dns.cloudflare.com. 2413220953 10000 2400 604800 1800

FAQ

Frequently Asked Questions

View all

This domain is analyzed as part of cside's domain directory to identify third-party scripts and their purposes. The summary provides information about what services, tools, or scripts this domain hosts, helping website owners understand which third-party services are being loaded on their sites.

The risk score is calculated based on multiple security factors including SSL certificate validity, DNSSEC status, domain registration details, and historical security data. A higher score indicates lower risk, while a lower score suggests potential security concerns that should be investigated.

The SSL certificate information shows whether the domain uses HTTPS encryption, when the certificate was issued, when it expires, and who issued it. This helps verify the domain's security posture and identify potential certificate-related vulnerabilities that could affect your website's security.

Third-party script domains can be compromised or used maliciously. By monitoring domain information like registration details, SSL certificates, and DNS records, you can identify suspicious changes, expired certificates, or domains that may pose security risks to your website and users.

Domain information is regularly scanned and updated to provide the most current security intelligence. The last scanned timestamp shows when the most recent analysis was performed, ensuring you have up-to-date information about the domain's security status.

If you identify a high-risk domain loading scripts on your website, you should investigate why it's being used, verify its legitimacy, and consider removing or replacing it if it's not essential. Use cside's platform to monitor and block suspicious third-party scripts to protect your users from potential security threats.

Subscribe to our newsletter to get the full picture

Stay updated with our latest news, offers and blog posts. Subscribe for exclusive updates delivered straight to your inbox.

Your inbox stays chill, we pop in monthly.

A pixelated, glitchy rendition of the cside shield
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead