bathandbodyworks.com

.com toplist crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 1993 ms crawled 2026-05-18

US · 151.101.67.52 · AS54113 Fastly, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Bath & Body Works: Body Care & Home Fragrances You'll Love | Bath & Body Works
Description
Welcome to Bath & Body Works! Discover our wide range of luxurious fragrances, skincare products, and home essentials. Shop our latest collections and enjoy exclusive offers today!
Language
en-US
Canonical
https://www.bathandbodyworks.com/
Translations
  • en
  • en-us
  • es-us

Technology

CDN
Cloudflare
CMS
Gatsby
Analytics
  • Cloudflare Insights

Third-party hosts loaded (2)

  • rapid-cdn.yottaa.com×1
  • static.cloudflareinsights.com×1

Social

Contact

Phone
Address
st Main Street,New Albany, OH 43054

Registration

Registrar
MarkMonitor Inc.
Created
1997-09-15
Expires
2026-09-14 117 days left
Updated
2024-08-13
Name servers
  • ns1-32.azure-dns.com
  • ns2-32.azure-dns.net
  • ns3-32.azure-dns.org
  • ns4-32.azure-dns.info

DNS records live

NS
  • ns1-32.azure-dns.com
  • ns2-32.azure-dns.net
  • ns3-32.azure-dns.org
  • ns4-32.azure-dns.info
MX
  • 10 bathandbodyworks-com.mail.protection.outlook.com
TXT
Show 9 TXT records
  • adobe-idp-site-verification=c1f402ca-7597-47f3-bcd4-8222a255a14e
  • include:production-store-bathandbodyworks.demandware.net
  • adobe-idp-site-verification=daf4b54d04dc06dbcca8b7620fec473f48136efd7ed690af46fa1f5a4f69d421
  • facebook-domain-verification=bds10lh2ag8jyn0yhovnm985cqh62p
  • ms54096357
  • v=spf include:alight.net ~all
  • include:spf-007b4202.pphosted.com
  • google-site-verification=JLhOZ3DzOJz9auv3pDWfFjAHR4Y58NYzbndricCoCZI
  • docusign=da491638-fdc4-4531-ad04-a97f4f483335

Email authentication strong

SPF
v=spf1 ip4:100.64.1.86 ip4:13.100.185.65 ip4:136.146.58.79 ip4:136.147.213.60 ip4:63.72.208.80 ip4:63.72.208.82 ip4:63.72.208.28 ip4:63.72.208.115 ip4:67.202.198.21 ip4:85.115.32.0/19 ip4:86.111.216.0/21 ip4:116.50.56.0/21 ip4:208.87.232.0/21 ip4:196.216.238.0/23 ip4:192.151.176.0/20 ip4:148.163.152.15 ip4:148.163.148.15 ip4:199.241.235.115 ip4:199.241.233.0/24 ip4:199.241.235.0/24 ip4:206.16.202.0/24 ip4:206.16.220.0/23 ip4:35.190.247.0/24 ip4:64.233.160.0/19 ip4:66.102.0.0/20 ip4:66.249.80.0/20 ip4:72.14.192.0/18 ip4:74.125.0.0/16 ip4:108.177.8.0/21 ip4:173.194.0.0/16 ip4:209.85.128.0/17 ip4:216.58.192.0/19 ip4:216.239.32.0/19 ip6:2001:4860:4000::/36 ip6:2404:6800:4000::/36 ip6:2607:f8b0:4000::/36 ip6:2800:3f0:4000::/36 ip6:2a00:1450:4000::/36 ip6:2c0f:fb50:4000::/36 ip4:172.217.0.0/19 ip4:172.217.32.0/20 ip4:172.217.128.0/19 ip4:172.217.160.0/20 ip4:172.217.192.0/19 ip4:172.253.56.0/21 ip4:172.253.112.0/20 ip4:108.177.96.0/19 ip4:35.191.0.0/16 ip4:130.211.0.0/22 ip4:136.146.58.79 a:production.store.bathandbodyworks.demandware.net include:spf.protection.outlook.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; pct=100
policy: quarantine
DKIM
no key found at common selectors

Certificate (current)

Certainly Intermediate R1
from 2026-04-29 to 2026-05-29
Expires in 10 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.bathandbodyworks.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
img-src 'self' *.commercecloud.salesforce.com *.bathandbodyworks.com *.bathandbodyworks.ca data: *.yottaa.net bat.bing.com *.google.com *.tealiumiq.com *.smaato.net *.pubmatic.com *.rubiconproject.com *.doubleclick.net *.casalemedia.com *.3lift.com *.ads.audio.thisisdax.com *.analytics.yahoo.com *.bazaarvoice.com *.brightcove.com *.brightcovecdn.com *.brsrvr.com *.cookielaw.org *.curalate.com *.dotomi.com *.googleapis.com *.gstatic.com *.mountain.com *.omtrdc.net *.onetrust.com *.openx.net *.paypalobjects.com *.pinterest.com *.zineone.com *.datadoghq.com ads.stickyadstv.com agentcore.s3.amazonaws.com aivo-assets.s3.amazonaws.com ap.lijit.com assets-qelplatam.s3.amazonaws.com bathandbodyworkscc.zendesk.com bh.contextweb.com cdn.cookielaw.org cdn.jsdelivr.net cm.everesttech.net contextual.media.net crb.kargo.com cs.openwebmp.com dpm.demdex.net exchange-match.mediaplex.com https://www.googletagmanager.com/td ib.adnxs.com idsync.live.streamtheworld.com idsync.rlcdn.com match.adsrvr.org mat
strict-transport-security
max-age=31557600

Links to (7)

Linked from (1)