aew.com

.com crawl

First seen 2026-04-16 · Last seen 2026-05-16 · ok HTTP/1.1 200 3457 ms crawled 2026-05-11

US · 18.217.122.90 · AS16509 Amazon.com, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
AEW Global Real Estate Investment Management Services
Language
en

Technology

Server
Apache
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • maxcdn.bootstrapcdn.com×1
  • px.ads.linkedin.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

Registration

Registrar
Network Solutions, LLC
Created
1995-05-12
Expires
2031-05-13 1819 days left
Updated
2026-03-14
Name servers
  • ns-1137.awsdns-14.org
  • ns-1726.awsdns-23.co.uk
  • ns-393.awsdns-49.com
  • ns-783.awsdns-33.net

DNS records live

NS
  • ns-1137.awsdns-14.org
  • ns-1726.awsdns-23.co.uk
  • ns-393.awsdns-49.com
  • ns-783.awsdns-33.net
MX
  • 10 mxa-000ff301.gslb.pphosted.com
  • 10 mxb-000ff301.gslb.pphosted.com
  • 20 mx0a-000ff301.pphosted.com
  • 20 mx0b-000ff301.pphosted.com
TXT
Show 9 TXT records
  • google-site-verification=F6tvKURA2tVb_-Tj0YOdI7kOMQTwkkJLw9UFNEkR-dA
  • miro-verification=b6e55080793c033f74c128ab76de8a20367032c1
  • onetrust-domain-verification=5419b574d59a42209738234c9492482a
  • smartsheet-site-validation=wGufIcM-2kxf2zTf4nzavMfPnMCffEIB
  • MS=ms26211265
  • at6NZxiJG/wlcwhRHf0koKQ1ob44CbjkpZqTFc6BFGo6DbQ2CMXCrZTE97H7c0KoEwypuX3wOTKk0KPTAbqpsQ==
  • atlassian-domain-verification=qlx0JmBOAR4dds2KqzB2bIyg4085gXKCDsVQdPnXtVk26NU6sxBS5wX1d04ByZze
  • canva-site-verification=_g3xtyhIFj-lC6KALRQduw

Email authentication partial

SPF
v=spf1 ip4:67.231.152.201/32 ip4:67.231.144.205/32 ip4:66.37.37.0/24 include:_spf.act-on.net ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:aew.dmarc@aew.com; ruf=mailto:aew.dmarc@aew.com; fo=1
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

R12
from 2026-04-04 to 2026-07-03
Expires in 44 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.aew.com/eu

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: vimeo.com *.vimeo.com youtube.com *.youtube.com aew.com *.aew.com apple.com *.apple.com podbean.com *.podbean.com insuranceaum.com *.insuranceaum.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.typekit.net js.stripe.com *.craft-cdn.com *.craftcms.com snap.licdn.com ; frame-ancestors 'self' ;
strict-transport-security
max-age=63072000; includeSubDomains

Links to (3)

Linked from (3)