anthropologie.com
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Cookie consent
-
- OneTrust
Third-party hosts loaded (5)
- images.ctfassets.net×18
- anthropologie501z.btttag.com×1
- cdn.cookielaw.org×1
- images.urbndata.com×1
- js.datadome.co×1
Registration
- Registrar
- SafeNames Ltd.
- Created
- 1996-05-01
- Expires
- 2027-05-02 347 days left
- Updated
- 2025-05-31
- Name servers
-
- ns-cloud-a1.googledomains.com
- ns-cloud-a2.googledomains.com
- ns-cloud-a3.googledomains.com
- ns-cloud-a4.googledomains.com
DNS records live
- NS
-
- ns-cloud-a1.googledomains.com
- ns-cloud-a2.googledomains.com
- ns-cloud-a3.googledomains.com
- ns-cloud-a4.googledomains.com
- MX
-
- 1 smtp.google.com
- TXT
-
Show 19 TXT records
mk-org-sso-0be0fb7a-9ec7-4807-908e-2cc73698f58canthropic-domain-verification-gaxn1f=k0DIk9KG3qSBRHDXgJkrBPjHOklaviyo-site-verification=VBdPtRMS=ms49295059atlassian-domain-verification=Un85mZ7js3qd2+qqu26LGJYwU2wzrUw7t+0HeyzXR/jLq+6kKPis3/YXSddxqZ6fMS=ms605607511w527zzwvy8n7bhs58v4z7938jlw625sDosY5BVEYOzPfb4PDE7zbqihh64dgdQ2YJdzxiBJeBcr2cgcXSjwKkbhWjyI+PTYtitKyEKPNzdgWh5ZkKiaNw==facebook-domain-verification=jwc6nsfi6u8bt1i6wgey8cpl0znpgsdatadome-domain-verify=wGGFzaMkgsCLVvt93T0EmSoVI38z92Pbgoogle-site-verification=GnEvnk6fkGm475B3P1Kile1QsT14h33OmpQ1KOrb1Mcairtable-verification=a79dabd2479008c7534d7353c38527cch0w81b352xp7ctx1z6ppdsqrg80p7644google-site-verification=moQieoa7dXEgDh9CPmhHlJ4teWUGVSdDTjjhPukBeO4j17js8zk0cx0m1gzf9g9fz9lcfcy4bfhvstdn8svryjyxvy0hwr55ns50x20gyfpZOOM_verify_JSLJpBl3R0-WgZk5tjnJogfigma-domain-verification=0a0ccb406aedd68427246933809aad17d680199e71c9928440c606f0b4dee3c7-1744727740stripe-verification=f54191bf44982021ae8535e8b12a9f006e4df91f6fb51261041fe803e66d38c1
Email authentication partial
- SPF
-
v=spf1 ip4:209.11.206.190/32 ip4:216.183.124.160/27 ip4:12.178.224.80/28 ip4:64.18.0.0/20 ip4:208.255.148.64/26 ip4:65.242.66.128/26 ip4:164.109.50.45/32 ip4:204.115.126.0/23 ip4:198.135.28.0/22 ip4:198.135.30.120/32 ip4:23.96.125.248/32 ip4:23.96.126.101/32 include:spf.protection.outlook.com include:spf.mtasv.net include:_spf.google.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCexuOSo9iMnvlneohvueloYxXJ8YFxT7Nz4bTDEEK4ef5EWN7UgICgrWgoT9GGzKzfLTWoLbQ0R2oQ/nNR36… - selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6wEK2/y3A6vJwu1NX1qfRsYM8v/7Nzz4oz/0i+BgUJz7ey0xWNX56MesW/33JMvT55JTANIQc2XowC…
selectors probed - google:
Certificate (current)
WR3
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://*.anthropologie.com; script-src 'self' 'nonce-HJt0VQsc/kgGsQKMWmS5W8C8ZJdTKALl' 'strict-dynamic' 'unsafe-eval' https:; connect-src 'self' https: wss://*.noibu.com; img-src 'self' * data: blob:; font-src 'self' data: https:; style-src 'self' 'unsafe-inline' https:; media-src 'self' https://*.ctfassets.net https://*.scene7.com https://*.urbndata.com https://*.cloudfront.net https://*.api.bazaarvoice.com https://images.anthropologie.com https://static.quiq-cdn.com; frame-src 'self' https://*.force.com https://*.pinterest.com https://*.stripe.com https://www.facebook.com https://*.krxd.net https://*.doubleclick.net https://www.google.com https://www.youtube.com https://player.vimeo.com https://*.attn.tv https://*.qualtrics.com https://*.salesforce.com https://*.8x8.com https://www.googletagmanager.com/ https://*.jebbit.com https://gmurphy2018.wufoo.com https://*.adsrvr.org https://*.flashtalking.com https://*.babylist.com https://pay.google.com https://*.liadm.co- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-resource-policy
same-site