childrensplace.com
HTML metadata
Technology
- CDN
- Akamai
- CMS
- Next.js
Third-party hosts loaded (16)
- assets2.theplace.com×71
- assets.theplace.com×28
- assets.adobedtm.com×1
- cdn.dynamicyield.com×1
- cdn.quantummetric.com×1
- dpm.demdex.net×1
- origin.xtlo.net×1
- rcom.dynamicyield.com×1
- s.go-mpulse.net×1
- search.unbxd.io×1
- st.dynamicyield.com×1
- tagtracking.vibescm.com×1
- tcp-sync.quantummetric.com×1
- universal.iperceptions.com×1
- web-assets.stylitics.com×1
- widget-api.stylitics.com×1
Social
Contact
- Address
- 500 Plaza Dr, 07094, Secaucus, NJ, US
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 1996-08-01
- Expires
- 2029-07-31 1169 days left
- Updated
- 2019-08-05
- Name servers
-
- pdns1.cscdns.net
- pdns2.cscdns.net
DNS records live
- NS
-
- pdns1.cscdns.net
- pdns2.cscdns.net
- MX
-
- 10 smtp.childrensplace.com
- 10 smtp2.childrensplace.com
- TXT
-
Show 10 TXT records
apple-domain-verification=zFTDDjn0oSJCp2HrMS=D3BC2FDCF769300CB4468CEEBA7783A3EEF9A14Cfacebook-domain-verification=c6f1ac97epfr6lj89lxxybfmu2lk0zgoogle-site-verification=BddF620PQrno_VQVkLbDSK3P4LJgSufrCXEng-2OE4wgoogle-site-verification=sVweYzYiatT0vGSZSpkFR8YtSnkfTO380EAvybi6FxAapple-domain-verification=lpi0W0KBZVG2OJrfxA05aiL8gTp_0fFERl4HBND-KIwapple-domain-verification=nEtL8YQ78y6LrVeuEQcsd2ZF-7ehcgl47uuXkNa-W_INJStIKgapME5UX/BrZ/c3kQ9g5iNeQp+dEKb/eMhY8SqMva8BVUtM2KOAHl1+mcRSWbc7kbqE5G6x2+MxkdM2A==MS=ms78037207tcpblogdev.azurewebsites.net
Email authentication strong
- SPF
-
v=spf1 a mx ip4:68.232.131.84 ip4:193.122.180.2/32 ip4:68.232.137.173 ip4:208.117.51.251 ip4:167.89.10.254 ip4:206.31.43.246 ip4:206.24.3.30 ip4:193.122.180.2 ip4:129.213.68.92 ip4:69.8.223.141 ip4:192.40.44.169 ip4:192.40.44.140 ip4:192.40.44.100 include:ipcampaign.iperceptions.com include:amazonses.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_agg@auth.returnpath.net; ruf=mailto:dmarc_afrf@auth.returnpath.netpolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9h+5qjSYgJ58Z7+we5yYYV8/oGAzioCvfFLRutQSYH9a2bLWaqXB9EhRJ7NfGXAyXqocuSsJgD0Z1K7MHJd… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAubviWW1/uAvFMW/VX8DqnXOH9i/VEhH0lQuVEhWsRRLna/qodhhTxw80O87953RklbrsPncI6CpRNJ… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsiqgGQWuZZ8x20bG8JHS+hQ1SvTZCR+ErQyMWQsszumi89Z1uZpIyZ4fbeLo6bhG3yEvDfp2OgJ77iZlYY… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDCuf0bC7uN3nMh+ILTMQo2pZRlVoexCD9SPJ+/nkmNuNnQU+D2QcW7MF+RA9zi/zdp6/ka7ziNPjyeGXCT5NPhW…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 174 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src blob: 'self' 'unsafe-inline' ws: wss: data: 'unsafe-eval' *.gymboree.com *.childrensplace.com *.rewardstyle.com dpm.demdex.net tcp.demdex.net *.xtlo.net *.akstat.io *.akamaihd.net *.go-mpulse.net *.adobedtm.com *.google.com *.googleapis.com *.bazaarvoice.com *.getcandid.com *.candid.io *.quantummetric.com *.omniture.com *.vibescm.com search.unbxd.io *.braintreegateway.com *.braintree-api.com *.borderfree.com *.briteverify.com *.raygun.io *.gstatic.com *.theplace.com *.omtrdc.net *.paypal.com *.paypalobjects.com *.iperceptions.com *.melissadata.net *.facebook.net *.facebook.com *.stylitics.com stylitics-ampersand-production.sfo2.cdn.digitaloceanspaces.com comenity.net *.netdna-ssl.com *.comenity.net *.fiftyone.com *.omtrdc.net *.demdex.net *.channeladvisor.com *.impactradius-event.com *.googletagmanager.com *.micpn.com *.bing.com *.filepicker.io *.cloudinary.com *.cloudfront.net *.theplace.com *.netdna-ssl.com *.filepicker.io *.iesnare.com *.googleadservices.com *.steelhouse- strict-transport-security
max-age=15768000 ; includeSubDomains- cross-origin-resource-policy
cross-origin