clubmahindra.com

.com crawl

First seen 2026-04-30 · Last seen 2026-05-19 · ok HTTP/1.1 200 9176 ms crawled 2026-05-08

US · 172.64.150.160 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Holiday at 140+ Resorts in India and Abroad with Club Mahindra
Description
Invest in a lifetime of wonderful holiday memories and get access to 140+ resorts across India and the world with Club Mahindra. Join The Club Now!
Canonical
https://www.clubmahindra.com
Translations
  • en

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager
Fonts
  • Adobe Fonts
  • Google Fonts
Third-party hosts loaded (9)
  • fonts.googleapis.com×5
  • cdn.jsdelivr.net×3
  • cdnjs.cloudflare.com×3
  • www.googletagmanager.com×2
  • clubmahindra.gumlet.io×1
  • toolassets.haptikapi.com×1
  • use.typekit.net×1
  • www.facebook.com×1
  • www.google.com×1

Social

Contact

Phone

Registration

Registrar
Network Solutions, LLC
Created
1997-09-02
Expires
2034-09-01 3025 days left
Updated
2024-09-01
Name servers
  • cass.ns.cloudflare.com
  • ernest.ns.cloudflare.com

DNS records live

NS
  • cass.ns.cloudflare.com
  • ernest.ns.cloudflare.com
MX
  • 0 clubmahindra-com.mail.protection.outlook.com
TXT
  • google-site verification=kbkM5TPK67Eu9KBTcjeMoEl8ll _UJ2QsgCUSN1hkEr8
  • 2cYJo+uRtUi2YPgA6lHrd0UKsd0nIuyJZAPFDJy0gAzqsMbTcQsengSNjS75bKoYHZkJApDmQAFYaJL8SlSNNw==
Verified for
  • Google
  • Meta
  • Microsoft 365

Email authentication partial

SPF
v=spf1 ip4:59.163.96.77 ip4:59.163.96.66 ip4:59.163.96.67 ip4:59.163.98.21 ip4:115.112.232.139 ip4:52.172.206.186 ip4:52.172.190.198 include:spf.protection.outlook.com include:authsmtp.com include:relianceada.com include:_spf.rediffmailpro.com include:mahindraholidays.com ip4:208.95.133.25 -all
strict (-all)
DMARC
v=DMARC1; p=none; pct=100; rua=mailto:itsecurity@clubmahindra.com; ruf=mailto:itsecurity@clubmahindra.com
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-04-14 to 2026-07-13
Expires in 53 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.clubmahindra.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' *.haptikapi.com *.firsthive.com *.hellohaptik.com https: data: ws: blob: https://cdn.jsdelivr.net https://*.jsdelivr.net; frame-src 'self' *.nitrocommerce.ai https://x.nitrocommerce.ai/nitro.js https://t.makehook.ws https://*.gotrackier.io *.googletagmanager.com *.kuula.co https://kuula.co https://trk.clmbtrck.in *.youtube.com *.clubmahindra.com *.airda.org *.google.com *.firsthive.com *.googleapis.com *.gumlet.com *.gumlet.io *.notifyvisitors.com *.facebook.com *.doubleclick.net; frame-ancestors 'self' *.clubmahindra.com *.airda.org *.google.com *.firsthive.com *.googleapis.com *.gumlet.com *.gumlet.io *.notifyvisitors.com *.facebook.com *.doubleclick.net; object-src 'none'; font-src 'self' https://*.jsdelivr.net https://*.typekit.net https://*.gstatic.com *.taggbox.com *.bootstrapcdn.com *.firsthive.com *.googleapis.com *.gstatic.com cdn.rawgit.com *.haptikapi.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.sharethis.com *.cleve
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (6)

Linked from (1)