caruso.com

.com crawl

First seen 2026-05-10 · Last seen 2026-05-10 · ok HTTP/1.1 200 2488 ms crawled 2026-05-16

US · 23.185.0.4 · AS54113 Fastly, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Homepage - Caruso
Language
en
Generator
WordPress 6.9.4
Canonical
https://caruso.com/

Open Graph

url
https://caruso.com/
title
Homepage - Caruso
locale
en_US
site name
Caruso

Technology

Server
nginx
CMS
WordPress
Social widgets
  • YouTube Embed

Third-party hosts loaded (2)

  • code.jquery.com×1
  • www.youtube.com×1

Contact

Phone

Registration

Registrar
GoDaddy.com, LLC
Created
1995-02-21
Expires
2027-02-22 277 days left
Updated
2026-02-23
Name servers
  • ns-1251.awsdns-28.org
  • ns-17.awsdns-02.com
  • ns-1835.awsdns-37.co.uk
  • ns-612.awsdns-12.net

DNS records live

NS
  • ns-1251.awsdns-28.org
  • ns-17.awsdns-02.com
  • ns-1835.awsdns-37.co.uk
  • ns-612.awsdns-12.net
MX
  • 0 caruso-com.mail.protection.outlook.com
TXT
  • ppe-688db49fdbba959568dc
Verified for
  • Anthropic
  • Apple
  • Atlassian
  • Google
  • Microsoft 365
  • Zoom

Email authentication partial

SPF
v=spf1 include:spf1.caruso.com include:spf2.caruso.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwy9UXP61iGlTug65wTObo7mWaa2cOoXRUfH0kL/ZWRYH3FADX27Mfl8aOdUXX9S2CpeiNOEvgkgYTcuqyW…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQ+AyT1Nh8ivA1qsYmlFibKABkQWIRFvFL5fow9OBoRraZQEomGd0yjpRnIWYmxojlydalfudXPon2T2bEd+YGmw…
selectors probed

Certificate (current)

R12
from 2026-05-04 to 2026-08-02
Expires in 74 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://caruso.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src * data: blob: 'self'; script-src 'self' api.privacy-center.org sdk.privacy-center.org *.didomi.io donate.mastercard.com maps.googleapis.com www.gstatic.com *.adroll.com www.youtube.com bam.nr-data.net code.jquery.com rum-collector-2.pingdom.net analytics.google.com d31qbv1cthcecs.cloudfront.net js.gleam.io js-agent.newrelic.com rum-static.pingdom.net static.ads-twitter.com www.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net cdn.privacy-mgmt.com *.google-analytics.com *.googletagmanager.com ajax.googleapis.com *.facebook.com *.fbcdn.net *.facebook.net *.google-analytics.com *.google.com 127.0.0.1:* 'unsafe-inline' 'unsafe-eval' blob: data: 'self';style-src data: blob: 'unsafe-inline' *; connect-src 'self' api.privacy-center.org sdk.privacy-center.org *.didomi.io https://www.google.com donate.mastercard.com maps.googleapis.com www.gstatic.com *.adroll.com www.youtube.com bam.nr-data.net rum-collector-2.pingdom.net analytics.google.com d31qbv1cthcecs.
strict-transport-security
max-age=31622400; includeSubDomains; preload

Links to (4)

Linked from (1)