cormarcarpets.co.uk

.uk crawl

First seen 2026-05-06 · Last seen 2026-05-13 · ok HTTP/1.1 200 5860 ms crawled 2026-05-13

GB · 88.98.24.72 · AS13037 Zen Internet Ltd

Reputation 100/100

Classifying

HTML metadata

Title
Cormar Carpets: Award Winning Quality Carpet Manufacturer
Description
Cormar Carpets are a UK based carpet manufacturer. Explore our award winning range of carpets here including wool, synthetic and blended carpets today.
Language
en
Canonical
https://www.cormarcarpets.co.uk/

Open Graph

url
https://www.cormarcarpets.co.uk/
title
Cormar Carpets
site name
Cormar Carpets

Technology

Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.googleapis.com×3
  • fonts.gstatic.com×1
  • www.googletagmanager.com×1

Social

Contact

Address
Brookhouse Mill, Holcombe Road, BL8 4HR, Bury, Greater Manchester, United Kingdom

Registration

Registrar
Zen Internet Limited
Created
2000-03-07
Expires
2027-03-07 290 days left
Updated
2026-01-27
Name servers
  • ns0.zen.co.uk.
  • ns1.zen.co.uk.

DNS records live

NS
  • ns0.zen.co.uk
  • ns1.zen.co.uk
MX
  • 5 eu-smtp-inbound-1.mimecast.com
  • 5 eu-smtp-inbound-2.mimecast.com
TXT
Show 5 TXT records
  • LJFyJGePxvTHq1vQ1ce232Uk1GbD5G1rbiVyVakUPNoOPljGBLiPlIGKKK1gWVAB9hvigtixbp1kX7/lQkiw7Q==
  • sophos-domain-verification=ed03f5a3795c6026819643847af2338ab8fa801443ce8dc145390b653703d532
  • 0ed1fe018a06555c07bbd2436993b300be15cb4b68
  • sophos-domain-verification=f437dc2c4bcb8623069a9bf563e8507ca15af55b
  • mandrill_verify.h0Lphk74JCsYxDFF-AIpjw
Verified for
  • Apple
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:eu._netblocks.mimecast.com include:u1535540.wl041.sendgrid.net include:u14098017.wl018.sendgrid.net include:mail.zendesk.com include:_spf.tacklephishing.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; pct=75; rua=mailto:rua@cormarcarpets.co.uk;
policy: reject (enforced) · pct=75
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnhyAlKBD8HU9QKhdaDo1P6/OhufyJLjBrnpoLDUP3NS/mzDvkPmT4vwzjY2p/dxKoknfAEwMXREMN+L07c…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDSxtlm60JucnhIcVfH47iJh99ItioAu2wbSyu28mvffUvKpD8krVarz7sSZNRtDsheRjvmK6R/ooaI+BxfHz8JDh…
selectors probed

Certificate (current)

R12
from 2026-05-07 to 2026-08-05
Expires in 77 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.cormarcarpets.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(),autoplay=(),camera=(),display-capture=(),encrypted-media=(),fullscreen=(),gamepad=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),sync-xhr=(self),usb=(),screen-wake-lock=(),web-share=(),xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
default-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://static.hotjar.com https://connect.facebook.net https://s.pinimg.com https://bat.bing.com https://survey.survicate.com https://googleads.g.doubleclick.net https://*.clarity.ms https://ct.pinterest.com https://script.hotjar.com; script-src-elem 'self' 'unsafe-inline' https://www.google-analytics.com https://www.googletagmanager.com https://static.hotjar.com https://connect.facebook.net https://s.pinimg.com https://bat.bing.com https://survey.survicate.com https://*.clarity.ms https://googleads.g.doubleclick.net https://ct.pinterest.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://script.hotjar.com https://api.ideal-postcodes.co.uk https://pagead2.googlesyndication.com https://*.moatads.com https://*.addthis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://ad.doubleclick.net https://bat.bing.com https://www.facebook.com https://w
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (1)