always.com

.com crawl

First seen 2026-04-23 · Last seen 2026-05-17 · ok HTTP/1.1 200 20908 ms crawled 2026-05-17

US · 150.171.109.34 · AS8075 Microsoft Corporation

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Always® Feminine Products and Menstrual Information
Description
Find all the Always feminine products and menstrual information that you need in order to feel comfortable and clean every day of the month.
Language
EN

Open Graph

title
Always Feminine Products and Menstrual Information | Always.com
description
Find all the Always feminine products and menstrual information that you need in order to feel comfortable and clean every day of the month.

Technology

CDN
Azure Front Door
CMS
Next.js
Analytics
  • Google Analytics
  • Google Tag Manager
Cookie consent
  • OneTrust

Third-party hosts loaded (6)

  • images.ctfassets.net×27
  • www.googletagmanager.com×2
  • c.lytics.io×1
  • cdn.cookielaw.org×1
  • cdn.segment.org×1
  • www.google-analytics.com×1

Social

Registration

Registrar
CSC Corporate Domains, Inc.
Created
1995-08-07
Expires
2026-08-06 79 days left
Updated
2025-08-02
Name servers
  • ns1-08.azure-dns.com
  • ns2-08.azure-dns.net
  • ns3-08.azure-dns.org
  • ns4-08.azure-dns.info

DNS records live

NS
  • ns1-08.azure-dns.com
  • ns2-08.azure-dns.net
  • ns3-08.azure-dns.org
  • ns4-08.azure-dns.info
MX
  • 10 alterdial.uu.net
  • 100 mail.uu.net
TXT
  • 7632-74C5-7355-C1DC-D07A-B5F7-9111-84B0
  • google-site-verification=1s0uBuGF6StBaP_FK8nHEQeboQkfk-e4FQDk9np8nGU
  • facebook-domain-verification=ojgbe0rn01zqbxw28gv1qs17xsf7cx

Email authentication weak

SPF
not published
DMARC
v=DMARC1; p=none; fo=1; ri=3600; rua=mailto:procter-gamble@rua.dmp.cisco.com; ruf=mailto:procter-gamble@ruf.dmp.cisco.com
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

Sectigo Public Server Authentication CA OV R36
from 2025-07-04 to 2026-08-04
Expires in 77 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.always.com/en-us

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self' https://mw-ar-recom-prod.pgapi.io/; media-src 'self' https://*.fireworktv.com; style-src 'self' 'unsafe-inline' *; img-src https://* 'self' data: https: blob:; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; frame-src *; frame-ancestors * 'self' data: https: blob:
strict-transport-security
max-age=31536000; includeSubdomains; preload

Links to (9)

Linked from (2)