coldstreamequestrian.co.uk

.uk crawl

First seen 2026-04-19 · Last seen 2026-05-16 · ok HTTP/1.1 200 3775 ms crawled 2026-05-13

GB · 139.162.255.58 · AS63949 Akamai Connected Cloud

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Coldstream Equestrian - Homepage
Description
Contemporary and timeless horse riding products from Coldstream Equestrian, designed to provide long-lasting durability and comfort for the avid horse rider.
Language
en

Technology

Server
nginx
Analytics
  • Google Tag Manager
  • Hotjar
Fonts
  • Google Fonts
Social widgets
  • Vimeo Embed
Third-party hosts loaded (14)
  • player.vimeo.com×3
  • cdnjs.cloudflare.com×2
  • code.jquery.com×2
  • fonts.googleapis.com×2
  • snapppt.com×2
  • stackpath.bootstrapcdn.com×2
  • www.googletagmanager.com×2
  • battles.us7.list-manage.com×1
  • chimpstatic.com×1
  • coldstreamequestrian.us7.list-manage.com×1
  • embed.tawk.to×1
  • static.hotjar.com×1
  • www.facebook.com×1
  • www.instagram.com×1

Social

Registration

Registrar
Ionos SE
Created
2019-03-07
Expires
2027-03-07 290 days left
Updated
2026-03-06
Name servers
  • ns1018.ui-dns.de.
  • ns1037.ui-dns.biz.
  • ns1098.ui-dns.org.
  • ns1105.ui-dns.com.

DNS records live

NS
  • ns1018.ui-dns.de
  • ns1037.ui-dns.biz
  • ns1098.ui-dns.org
  • ns1105.ui-dns.com
MX
  • 0 coldstreamequestrian-co-uk.mail.protection.outlook.com
Verified for
  • Google

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

R12
from 2026-05-10 to 2026-08-08
Expires in 79 days

HTTP security headers

Header hygiene 95/100 Checked live page: https://coldstreamequestrian.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=*,autoplay=*,camera=*,display-capture=*,document-domain=*,encrypted-media=*,fullscreen=*,geolocation=*,gyroscope=*,magnetometer=*,microphone=*,midi=*,payment=*,picture-in-picture=*,publickey-credentials-get=*,screen-wake-lock=*,sync-xhr=*,usb=*,web-share=*,xr-spatial-tracking=*
x-content-type-options
nosniff
content-security-policy
default-src https: wss:;style-src https: data: 'unsafe-inline';script-src https: 'unsafe-inline' 'unsafe-eval';img-src https: blob: data: 'unsafe-inline';connect-src https: wss: feed:
strict-transport-security
max-age=31536000; includeSubDomains

Links to (3)

Linked from (2)