citybreak.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-15 · ok HTTP/1.1 200 3150 ms crawled 2026-05-07

US · 104.18.23.71 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Citybreak Enterprise | Citybreak Enterprise | Built for the inbound tourism
Description
Citybreak is for the inbound tourism industry. Package your and other operators products, distribute widely and get booked via your eCom and other channels.
Language
en
Canonical
https://www.citybreak.com/
Translations
  • en
  • fr
  • sv

Open Graph

url
https://www.citybreak.com/
title
Citybreak Enterprise | Built for the inbound tourism
site name
Citybreak Enterprise
description
Citybreak is for the inbound tourism industry. Package your and other operators products, distribute widely and get booked via your eCom and other channels.

Technology

CDN
Cloudflare
Analytics
  • Cloudflare Insights
Fonts
  • Font Awesome

Third-party hosts loaded (3)

  • cdn.jsdelivr.net×2
  • use.fontawesome.com×2
  • static.cloudflareinsights.com×1

Contact

Email
Phone

Registration

Registrar
Name SRS AB
Created
1998-10-14
Expires
2026-10-13 146 days left
Updated
2025-09-14
Name servers
  • kim.ns.cloudflare.com
  • mark.ns.cloudflare.com

DNS records live

NS
  • kim.ns.cloudflare.com
  • mark.ns.cloudflare.com
MX
  • 0 citybreak-com.mail.protection.outlook.com
TXT
Show 5 TXT records
  • 183r4o9ap8mhc7991n0p50retn
  • MS=ms33074967
  • _globalsign-domain-verification=R1-yJPMVhGDf_ltXoD03poOQvmag07JJ3HtB7LRFv-
  • google-site-verification=1pZh27aqsK4haoKTOvDk-AD4N6Ur2jeneCohaJMzMaY
  • yZUYaJsGdz6bWNiSjaoUhgmXU5NFYbFJlgDznoi30KOXa2EAT5+Xdi6O+jaaZaagIjeWWjElir0fzyN4yOMxmQ==

Email authentication strong

SPF
v=spf1 include:_spf.citybreak.com include:servers.mcsv.net include:spf.protection.outlook.com include:145604144.spf03.hubspotemail.net ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:a3964d749d8d4eeaa2feeebc43506716@dmarc-reports.cloudflare.net,mailto:s86jtnkm@rua.eu.dmarcmanager.app
policy: none (monitoring only)
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvkyTYrZiajdKB8XGLHyEgWHyiCjxKF5/bTJOF9yKVLm6KeMXa0Z2JLkRueKaePKrnj+6d58GoWYehRsQOX…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDfxTJW1hus9QHlFuIpzBOF5lPotzBpoAzjbJGgZWFvQUEuVKbQZdcMzKNvIW+oMI70tdgE+7hXNl2HgbrEUtqJ7J…
selectors probed

Certificate (current)

WE1
from 2026-04-24 to 2026-07-23
Expires in 64 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.citybreak.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' http: https: data: blob: wss:; worker-src * blob:; frame-ancestors 'self' localhost:* *.citybreak.com citybreak.com; report-uri https://www.citybreak.com/report-uri/enforce
strict-transport-security
max-age=15552000; includeSubDomains; preload

Links to (4)

Linked from (4)