brownleepress.com

.com crawl

First seen 2026-04-22 · Last seen 2026-05-12 · ok HTTP/1.1 200 5762 ms crawled 2026-05-16

US · 172.67.180.48 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

sector tech type homepage

HTML metadata

Title
Brownlee Press — Brownlee Press
Description
A performant frontend ecommerce starter template with Next.js 15 and Medusa.
Language
en

Open Graph

url
https://brownleepress.com
title
Brownlee Press
site name
Brownlee Press
description
Making printing...better.

Technology

CDN
Cloudflare
CMS
Next.js

Third-party hosts loaded (2)

  • brownlee-medusa.s3.us-east-2.amazonaws.com×31
  • s3.us-east-1.amazonaws.com×6

Registration

Registrar
GoDaddy.com, LLC
Created
2019-06-22
Expires
2026-06-22 33 days left
Updated
2026-04-20
Name servers
  • art.ns.cloudflare.com
  • venus.ns.cloudflare.com

DNS records live

NS
  • art.ns.cloudflare.com
  • venus.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com

Email authentication weak

SPF
not published
DMARC
v=DMARC1; p=none
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-04-20 to 2026-07-19
Expires in 61 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://brownleepress.com/us

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
default-src 'self'; font-src 'self' https://js.stripe.com; frame-src 'self' https://js.stripe.com https://hooks.stripe.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com; connect-src 'self' https://api.stripe.com https://js.stripe.com https://*.medusajs.app https://*.medusajs.site; img-src 'self' data: blob: https: http:; style-src 'self' 'unsafe-inline' https://js.stripe.com
strict-transport-security
max-age=86400; includeSubDomains; preload

Links to (1)

Linked from (1)