caribehilton.com
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- ka-p.fontawesome.com×4
- www.googletagmanager.com×2
- assets.adobedtm.com×1
- cdn.weatherapi.com×1
Social
Contact
- Phone
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 1998-01-31
- Expires
- 2027-01-30 254 days left
- Updated
- 2025-12-29
- Name servers
-
- asia1.akam.net
- asia9.akam.net
- eur5.akam.net
- eur6.akam.net
- ns1-104.akam.net
- ns1-7.akam.net
- use1.akam.net
- use4.akam.net
DNS records live
- NS
-
- asia1.akam.net
- asia9.akam.net
- eur5.akam.net
- eur6.akam.net
- ns1-104.akam.net
- ns1-7.akam.net
- use1.akam.net
- use4.akam.net
- MX
-
- 10 mail.caribehilton.com
- Verified for
-
Certificate (current)
R13
Expires in 28 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: cdnjs.cloudflare.com *.tripadvisor.com static.tacdn.com widget.ybug.io static.addtoany.com player.vimeo.com *.jscache.com kit.fontawesome.com *.youtube.com maps.googleapis.com assets.adobedtm.com *.branch.io *.trustarc.com *.link *.googletagmanager.com *.mplat-ppcprotect.com *.googleadservices.com *.sc-static.net *.yimg.jp *.taboola.com *.treasuredata.com *.facebook.net *.yimg.com *.doubleclick.net *.googleadservices.com *.micpn.com *.rezync.com *.pinimg.com *.bing.com *.licdn.com *.sojern.com *.rfihub.net *.boomtrain.com *.pinterest.com *.adsrvr.org *.quantserve.com dwin1.com sc-static.net *.snapchat.com *.dwin1.com *.rfihub.net *.rakuten.com *.linksynergy.com *.googleapis.com *.hilton.com *.presage.io *.quantcount.com *.teads.tv *.amazon-adsystem.com *.relay-t.io; style-src 'self' 'unsafe-inline' static.tacdn.com fonts.googleapis.com; img-src 'self' data: cdn.weatherapi.com secure.gravatar.com *.tripadvisor.com- strict-transport-security
max-age=31536000; preload