bandqgiftcard.com

.com crawl

First seen 2026-04-12 · Last seen 2026-05-20 · ok HTTP/1.1 200 3000 ms crawled 2026-05-20

GB · 172.166.112.101 · AS8075 Microsoft Corporation

Reputation 100/100

Classifying

HTML metadata

Title
Gift Cards - buy online, spend online or in-store
Description
B&Q Gift Cards, a DIY’ers dream to create their perfect project. Next day delivery is available as well as personalisation. Can be spent online at diy.com, or in any of our 300 stores.
Language
Document Language

Technology

Stack
ASP.NET
Analytics
  • Google Tag Manager

Third-party hosts loaded (4)

  • cookie-cdn.cookiepro.com×2
  • services.postcodeanywhere.co.uk×2
  • www.google.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone

Registration

Registrar
Nom-iq Ltd. dba COM LAUDE
Created
2014-12-16
Expires
2034-12-16 3131 days left
Updated
2025-02-07
Name servers
  • nsgbr.comlaude.co.uk
  • nssui.comlaude.ch
  • nsusa.comlaude.net

DNS records live

NS
  • nsgbr.comlaude.co.uk
  • nssui.comlaude.ch
  • nsusa.comlaude.net

Email authentication no MX

SPF
v=spf1 -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:102b7a32a370252@rep.dmarcanalyzer.com; ruf=mailto:102b7a32a370252@for.dmarcanalyzer.com; fo=1;
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

Starfield Secure Certificate Authority - G2
from 2025-07-30 to 2026-08-31
Expires in 102 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.bandqgiftcard.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src *; script-src * 'unsafe-inline'; script-src-elem * 'unsafe-inline'; script-src-attr * 'unsafe-inline'; style-src * 'unsafe-inline'; style-src-elem * 'unsafe-inline'; style-src-attr * 'unsafe-inline'; img-src * blob: data:; font-src *; connect-src *; media-src *; object-src *; child-src *; frame-src *; worker-src *; frame-ancestors *; form-action *; upgrade-insecure-requests; block-all-mixed-content
strict-transport-security
max-age=31536000

Links to (6)

Linked from (1)