doitbestonline.com

.com crawl

First seen 2026-04-14 · Last seen 2026-05-08 · ok HTTP/1.1 200 1192 ms crawled 2026-05-08

US · 69.67.205.25 · AS15144 Xymmetrix, LLC

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Do it Best | Hardware, Lumber & Building Materials Co-op
Description
Do it Best is the only US-based, member-owned comprehensive and fully integrated hardware, lumber and building materials buying cooperative in the home improvement industry.
Language
en-US
Generator
All in One SEO Pro (AIOSEO) 4.9.6.1
Canonical
https://www.doitbestonline.com/
Feeds

Technology

Server
Apache
CMS
WordPress
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • fonts.googleapis.com×3
  • cdnjs.cloudflare.com×2
  • www.google.com×2
  • www.googletagmanager.com×1

Social

Registration

Registrar
GoDaddy.com, LLC
Created
2019-01-02
Expires
2027-01-02 227 days left
Updated
2026-01-03
Name servers
  • ns1-01.azure-dns.com
  • ns2-01.azure-dns.net
  • ns3-01.azure-dns.org
  • ns4-01.azure-dns.info

DNS records live

NS
  • ns1-01.azure-dns.com
  • ns2-01.azure-dns.net
  • ns3-01.azure-dns.org
  • ns4-01.azure-dns.info
MX
  • 10 mail.xymmetrix.net
  • 100 proxima.xymmetrix.net

Email authentication partial

SPF
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-09 to 2026-07-08
Expires in 49 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.doitbestonline.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
deny
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: cdnjs.cloudflare.com *.google-analytics.com https://www.google-analytics.com *.googleapis.com https://www.google.com/js https://www.google.com/ads https://www.googletagmanager.com https://cloud.typography.com *.gstatic.com https://stats.g.doubleclick.net *.cloudfront.net https://www.youtube.com *.youtube.com https://app.termly.io https://i.ytimg.com https://yt3.ggpht.com https://static.doubleclick.net https://secure.quantserve.com https://snap.licdn.com https://rules.quantcount.com https://pixel.quantserve.com https://px.ads.linkedin.com http://www.google.com https://p.adsymptotic.com https://lbm.doitbestonline.com https://media.mydoitbest.com ; frame-src 'self' https://app.termly.io https://www.youtube.com https://www.google.com ; frame-ancestors 'self' https://www.doitbestcareers.com; base-uri 'none'; object-src 'none';
strict-transport-security
max-age=63072000

Links to (10)

Linked from (1)