crayola.com
HTML metadata
Technology
- CDN
- Cloudflare
Third-party hosts loaded (4)
- cdn.bc0a.com×1
- cdnjs.cloudflare.com×1
- se.monetate.net×1
- w.likebtn.com×1
Registration
- Registrar
- Nom-iq Ltd. dba COM LAUDE
- Created
- 1994-11-10
- Expires
- 2026-11-09 173 days left
- Updated
- 2025-10-10
- Name servers
-
- ns-1027.awsdns-00.org
- ns-1596.awsdns-07.co.uk
- ns-273.awsdns-34.com
- ns-851.awsdns-42.net
DNS records live
- NS
-
- ns-1027.awsdns-00.org
- ns-1596.awsdns-07.co.uk
- ns-273.awsdns-34.com
- ns-851.awsdns-42.net
- MX
-
- 10 mx1.hc2388-90.iphmx.com
- TXT
-
Show 19 TXT records
google-site-verification=vpiUrDfR_yssyOx0iwWJaEuxUOJk66L3OvsfURLsjroonetrust-domain-verification=b886de5b7433491db8f91992dd9c0467jmx4672x08g70kr0d633cvx7x1l8kz3kamazonses:4CJnUZ/g4VO/UB5XO3pvHIuF2bUTlBf397q/opWGsfo=8qm4t808g89c80moldsf7t4k45globalsign-domain-verification=DA9CA0BEB44A2E92BC09C084BA7A0E73amazon-business-verification=996763df3a2b689b4d531e1d776f82889aa89a9e099a73dbba714fcfafe22d95facebook-domain-verification=k2cviap8uua36xy73pgxxcrfckcduacanva-site-verification=iGAwOiiR7vnzcBlOdFPMAAjamf-site-verification=ztzkwPkf5g5GcUaYZIPWcgdocusign=5aa10f0d-7458-4477-ac38-2aa442eef764MS=ms86413063a226309d-f516-4353-afa8-edda2c913610globalsign-domain-verification=7AAFB9C1CFC9FAF2CE74A86FCA25BB926sl1kl35sf2qygkq20z74dt3sl4w5dg6_rn54x16ry9ww62tzhps5lingjokz9bmMS=ms37414576globalsign-domain-verification=4644C1C1E22BC8F1F0AA50625D728916airtable-verification=cb28e951a7908220526a4bb38b409d37
Email authentication strong
- SPF
-
v=spf1 a:mx1.hc2388-90.iphmx.com ip4:216.139.237.0/25 ip4:13.110.179.184 ip4:52.4.168.245 ip4:85.17.243.80/28 ip4:151.106.140.135 ip4:184.173.153.196 include:_spf.ultipro.com include:sendgrid.net include:spf.mailjet.com include:_spf.createsend.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarcreporting@crayola.com; ruf=mailto:dmarcreporting@crayola.com;policy: quarantine - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAujeBrxdIm6mczKxcyv9MCrzcHIi53WXYOC5uufpq/H+5KZC+/7yHdbruViY1jK6Rly6HLFRhN5oN6Rc87T… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDK120F6uF7fP9NmIzDai/k+LeJSlfA0BHTmT0uobgsNNAvBsKUztPOBCZCk3KeFuiFgWWbIqliAECBpe6mEyW4o/…
selectors probed - k2:
Certificate (current)
WE1
Expires in 29 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; script-src 'unsafe-inline' https://*.googleapis.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://apis.google.com https://*.google-analytics.com https://kit.fontawesome.com https://cdn.insight.sitefinity.com https://js.monitor.azure.com https://*.marker.io https://*.youtube.com 'self' https://cdn.bc0a.com https://*.bazaarvoice.com https://*.monetate.net 'unsafe-eval' https://api.astutebot.com https://bot.emplifi.io https://cdn.listrakbi.com https://s1.listrakbi.com https://onescript-recscont.listrakbi.com https://bl.listrakbi.com https://at1.listrakbi.com https://www.googletagmanager.com https://cdn.cookielaw.org https://services.listrak.com https://static.addtoany.com/ https://*.likebtn.com https://*.ipstack.com https://*.pricespider.com https://*.mapbox.com https://mediacdn.espssl.com https://*.listrakbi.com onescript-recscont.listrakbi.com https://*.crayola.com https://code.jquery.com https://connect.facebook.net https://googleads.g.doubleclick.ne- strict-transport-security
max-age=31536000; preload