bollandbranch.com

.com crawl

First seen 2026-04-24 · Last seen 2026-05-18 · ok HTTP/1.1 200 1708 ms crawled 2026-05-18

CA · 23.227.38.67 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Luxury Organic Bedding, Sheets & Towels | Boll & Branch® | Boll & Branch
Description
At Boll & Branch, we hold ourselves to a higher standard. Our organic bedding is toxin-free and Fair Trade Certified. Enjoy free shipping & returns on all U.S. orders of $100+.
Language
en
Canonical
https://www.bollandbranch.com/

Open Graph

url
https://www.bollandbranch.com/
title
Luxury Organic Bedding, Sheets & Towels | Boll & Branch® | Boll & Branch
description
At Boll & Branch, we hold ourselves to a higher standard. Our organic bedding is toxin-free and Fair Trade Certified. Enjoy free shipping & returns on all U.S. orders of $100+.

Technology

CDN
Cloudflare
CMS
Shopify
Cookie consent
  • OneTrust

Third-party hosts loaded (4)

  • cdn.shopify.com×65
  • cdn.sanity.io×9
  • cdn.cookielaw.org×1
  • shop.app×1

Social

Contact

Address
1200 Morris Turnpike, 07078, Short Hills, NJ, US

Registration

Registrar
GoDaddy.com, LLC
Created
2013-05-02
Expires
2035-05-02 3268 days left
Updated
2026-04-07
Name servers
  • ns-1474.awsdns-56.org
  • ns-1877.awsdns-42.co.uk
  • ns-216.awsdns-27.com
  • ns-740.awsdns-28.net

DNS records live

NS
  • ns-1474.awsdns-56.org
  • ns-1877.awsdns-42.co.uk
  • ns-216.awsdns-27.com
  • ns-740.awsdns-28.net
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 6 TXT records
  • 14ZZ7L
  • 41E4D4C4D0
  • ALIAS for n.ssl.shopify.com
  • _tuqowskjstuo6jvid4mjyik1xf03sl3
  • ca3-522cd7c36e5d44419010dfe8b79691b7
  • rippling-domain-verification=e0154f40e7738d3b
Verified for
  • 1Password
  • Apple
  • DocuSign
  • Google
  • Meta

Email authentication strong

SPF
v=spf1 include:_spf.google.com include:sendgrid.net include:mail.zendesk.com include:shops.shopify.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; pct=100; rua=mailto:email-deliverability@bollandbranch.com
policy: quarantine
DKIM
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFCiohyhRDA/ReMWnnSFkfykwR57DEvgY54psqRBSMeT200j7ji64kPz1ZVm2h2YgFq7Z8kV2fAnjlJXS/ah…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4w6eQpkTmhsfp38/LSv37t/lCm7DK+x1LBf6X74IYaKDfsPXRCQysrPmyEt9tOGZi9lPCNN3n+B1uUM4jF…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2AVEC4/+vILMoJ54zYflkyJa9RtDOOyXXYE0PVzZL+X48Pj31eXkRWfpLd+jqh1sYAz3xdrcc6XrKmxfKr…
selectors probed

Certificate (current)

E7
from 2026-04-13 to 2026-07-12
Expires in 52 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.bollandbranch.com/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
Header values
permissions-policy
web-share=(self "https://bollandbranch.hemsy.ai" "https://web-app-git-hemsy-v4-hemsy.vercel.app" "https://hemsy.ai"), clipboard-write=(self "https://bollandbranch.hemsy.ai" "https://web-app-git-hemsy-v4-hemsy.vercel.app" "https://hemsy.ai")
x-content-type-options
nosniff
content-security-policy
base-uri 'self'; default-src 'self' *.bollandbranch.io https://cdn.sanity.io https://cdn.shopify.com https://lh3.googleusercontent.com https://boll-branch-hydrogen.myshopify.com https://evs.segment.bollandbranch.com https://cdn.cookielaw.org https://static.zdassets.com https://assets.gotolstoy.com 'self' 'nonce-c24c32551f78565ea10c971598fa10f7' https://cdn.shopify.com https://shopify.com; frame-ancestors 'self' https://*.sanity.io https://www.sanity.io; style-src *.bollandbranch.io https://cdn-widgetsrepository.yotpo.com 'self' https://cdn-widget-assets.yotpo.com *.abtasty.com https://vjs.zencdn.net/7.8.4/video-js.css *.gotolstoy.com *.stockist.co https://fonts.googleapis.com https://hemsy.ai *.hemsy.ai *.alia-prod.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src *.bollandbranch.io https://1k4z419d.api.sanity.io wss://1k4z419d.api.sanity.io *.yotpo.com *.merchant-center-analytics.google *.merchant-center-analytics.goog https://app.backinstock.org https://checkout.bolland
strict-transport-security
max-age=31536000

Links to (4)

Linked from (1)