intercom.io
Gandi SAS
unsigned
Yes
Intercom.io is a communication platform that enables businesses to connect with customers and team members. Registered in 2011, it has a long and established history with reliable DNS settings, but lacks DNSSEC protection due to being unsigned.
Data on this page is collected by cside's crawler, which monitors third-party scripts across the public web.
Intercom
Category: customer-support
Description
Intercom is an AI-powered customer service platform with live chat, chatbots, and help center.
AI Review
The scripts from intercom.io and its CDN integrate customer messaging services into web applications, creating an iframe-based chat interface which facilitates real-time interactions. These scripts actively collect data during user interactions, particularly during payment processes, indicating a continuous presence on PCI-scoped pages that could raise data minimization concerns. Although the primary function is to enhance customer support and reduce abandonment through interactive features, their dependency on third-party APIs (including Intercom and Salesforce) introduces potential vulnerabilities related to supply chain security and user privacy. Additionally, the presence of obfuscation techniques in some scripts complicates transparency regarding data handling practices, prompting caution over user data management. Despite the absence of alert activity in the last week, which indicates stable operations, ongoing monitoring will be crucial to ensure that data collection practices remain non-intrusive and do not inadvertently capture sensitive payment information. Overall, the key risks stem from the broad data collection capabilities coupled with third-party dependencies, which could create avenues for unintentional data exposure. Organizations utilizing these scripts must ensure that collected data remains appropriately scoped and does not encompass sensitive payment details, particularly during critical interactions.
Script hostnames
Enabled
intercom.io is one of thousands of third-party scripts on the web.
Most sites run dozens of third-party scripts and can't say what each one does. cside monitors every script on your site and catches the ones that change or turn malicious.
| Hostname | Type | TTL | Priority | Content |
|---|---|---|---|---|
| intercom.io | NS | 172687 | ns-1478.awsdns-56.org. | |
| intercom.io | NS | 172687 | ns-1867.awsdns-41.co.uk. | |
| intercom.io | NS | 172687 | ns-661.awsdns-18.net. | |
| intercom.io | NS | 172687 | ns-97.awsdns-12.com. | |
| intercom.io | A | 15 | 18.173.121.82 | |
| intercom.io | A | 15 | 18.173.121.120 | |
| intercom.io | A | 15 | 18.173.121.70 | |
| intercom.io | A | 15 | 18.173.121.102 | |
| intercom.io | MX | 3600 | 10 | aspmx.l.google.com. |
| intercom.io | MX | 3600 | 20 | alt1.aspmx.l.google.com. |
| intercom.io | MX | 3600 | 20 | alt2.aspmx.l.google.com. |
| intercom.io | MX | 3600 | 30 | aspmx2.googlemail.com. |
| intercom.io | MX | 3600 | 30 | aspmx3.googlemail.com. |
| intercom.io | MX | 3600 | 30 | aspmx4.googlemail.com. |
| intercom.io | MX | 3600 | 30 | aspmx5.googlemail.com. |
| intercom.io | TXT | 60 | "44fe5751ed54509a8eb9b93b5304d15f36825314" | |
| intercom.io | TXT | 60 | "@7L^2cvvFFY" | |
| intercom.io | TXT | 60 | "TAILSCALE-tsR9uC78MVSXKWuTOMDP" | |
| intercom.io | TXT | 60 | "adobe-idp-site-verification=14d3a7a87dad24c14b77b4cf854ff2edcd833fe9ff6649dc8b40ae053f0aeb7a" | |
| intercom.io | TXT | 60 | "adobe-sign-verification=6b53472fcd37723d956a05b81966ec" | |
| intercom.io | TXT | 60 | "all-good-technology-inc-domain-verification-0exxdz=50vxx0vn2alRLBv7ZDLBsft1P" | |
| intercom.io | TXT | 60 | "anthropic-domain-verification-vg9n3z=HEiyqGokg2F1KX8RGg8xTDpvn" | |
| intercom.io | TXT | 60 | "apple-domain-verification=6WueY6qt9eXNiDGN" | |
| intercom.io | TXT | 60 | "atlassian-domain-verification=cvSYWtG+M8VZhvC5F3Xh+TdCgqGSgwCJD8yV9xB+ki17M+f+k7v8oWpzfHln8Xy1" | |
| intercom.io | TXT | 60 | "bugcrowd-verification=9f9a1549d203c31e96851d605187f335" | |
| intercom.io | TXT | 60 | "canva-site-verification=Gdlzk_G0P2WmO6LCmpkwFg" | |
| intercom.io | TXT | 60 | "cursor-domain-verification-8v636x=2iFMOHCI7ynmysN9t8SEcB33t" | |
| intercom.io | TXT | 60 | "d38xc8nflzxfm6.cloudfront.net" | |
| intercom.io | TXT | 60 | "docker-verification=4fc0635c-fdfe-4a0b-a513-7c6b1a8f0a8b" | |
| intercom.io | TXT | 60 | "docusign=36a72b16-7b53-4451-9c2b-ed8ddaa4fdd6" | |
| intercom.io | TXT | 60 | "docusign=5671c452-c1b5-463d-980a-42c6d0c0eaf7" | |
| intercom.io | TXT | 60 | "elevenlabs=1aH-vlhm6CdQMGtQETglCejQWKkrB4BJk9dcuV0FOZQ" | |
| intercom.io | TXT | 60 | "elevenlabs=a4CzfapvQzlOc4ocj66kx__z3bGNk45KuG9nhjhULUM" | |
| intercom.io | TXT | 60 | "google-site-verification=1XkbuV4wwZYSKVQ3viMyuIBR_2Kbu0TVOu59SssCWiI" | |
| intercom.io | TXT | 60 | "google-site-verification=EoBLTSecVYsuED-Y1lC6EwW0Q1iu9JLvE-AIi--nCco" | |
| intercom.io | TXT | 60 | "google-site-verification=OSOfG-mb3KUeEu7ZI0L2obMNOp4bZhLtBwCqMM7Al5s" | |
| intercom.io | TXT | 60 | "google-site-verification=PJaVXXgRe9jtml54j0qd1f7YB_7dGfKopsEQFUEQKSw" | |
| intercom.io | TXT | 60 | "google-site-verification=ez1F6KAmCudYI4EUyIhUJ2i4pKaoJONHPc3VMt2A58I" | |
| intercom.io | TXT | 60 | "google-site-verification=oFO8X3XmUG_4Q17VJ-kdvxjI_7lnWTPpm7Yd3uObAlY" | |
| intercom.io | TXT | 60 | "google-site-verification=pbKcc7lEi4kv7RhbT50x_Ev2wnIV5TcWcTeYWxS5rh8" | |
| intercom.io | TXT | 60 | "https://issues.sonatype.org/browse/OSSRH-64279" | |
| intercom.io | TXT | 60 | "jamf-site-verification=aked3xDSe3HcqRs1hkmCjQ" | |
| intercom.io | TXT | 60 | "jetbrains-domain-verification=eqj5zs6mlow55x1ab5rpkgj05" | |
| intercom.io | TXT | 60 | "linear-domain-verification=pmfpkwpbt5jg" | |
| intercom.io | TXT | 60 | "mgverify=3e1c1a7bc6cf0c9dd60c004038e141000ad7299f576b696ca7040b8c8fac7b40" | |
| intercom.io | TXT | 60 | "miro-verification=83c3039d09e9cd06b3e2935d6857d875d55c3edb" | |
| intercom.io | TXT | 60 | "openai-domain-verification=dv-Rpdv1vp3dWq5fhU72HogewTv" | |
| intercom.io | TXT | 60 | "slack-domain-verification=isIS2GuqMLlNw9zaOdHov3Jx7KF5AAJJnBUkIi2T" | |
| intercom.io | TXT | 60 | "spycloud-domain-verification=e49a0b79-2252-49d3-9412-67fb19f1427e" | |
| intercom.io | TXT | 60 | "status-page-domain-verification=ff8hq5rxx1pq" | |
| intercom.io | TXT | 60 | "stripe-verification=e4d49836a81144c2720bba6b3c5bd51275ea8d9378d9ebd3e4d2f17480f0c565" | |
| intercom.io | TXT | 60 | "v=spf1 include:_spf.google.com include:cmail1.com include:stspg-customer.com a:zgateway.zuora.com -all" | |
| intercom.io | TXT | 60 | "zapier-domain-verification-challenge=315daada-6ac1-4712-b559-50452e34dde4" | |
| intercom.io | SOA | 172800 | ns-97.awsdns-12.com. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 60 |
FAQ
Frequently Asked Questions
This domain is analyzed as part of cside's domain directory to identify third-party scripts and their purposes. The summary provides information about what services, tools, or scripts this domain hosts, helping website owners understand which third-party services are being loaded on their sites.
The risk score is calculated based on multiple security factors including SSL certificate validity, DNSSEC status, domain registration details, and historical security data. A higher score indicates lower risk, while a lower score suggests potential security concerns that should be investigated.
The SSL certificate information shows whether the domain uses HTTPS encryption, when the certificate was issued, when it expires, and who issued it. This helps verify the domain's security posture and identify potential certificate-related vulnerabilities that could affect your website's security.
Third-party script domains can be compromised or used maliciously. By monitoring domain information like registration details, SSL certificates, and DNS records, you can identify suspicious changes, expired certificates, or domains that may pose security risks to your website and users.
Domain information is regularly scanned and updated to provide the most current security intelligence. The last scanned timestamp shows when the most recent analysis was performed, ensuring you have up-to-date information about the domain's security status.
If you identify a high-risk domain loading scripts on your website, you should investigate why it's being used, verify its legitimacy, and consider removing or replacing it if it's not essential. Use cside's platform to monitor and block suspicious third-party scripts to protect your users from potential security threats.
Subscribe to our newsletter to get the full picture
Stay updated with our latest news, offers and blog posts. Subscribe for exclusive updates delivered straight to your inbox.
Your inbox stays chill, we pop in monthly.