esteelauder.co.uk
HTML metadata
Technology
- CDN
- Akamai
- CMS
- Drupal
Third-party hosts loaded (30)
- www.esteelauder-me.com×44
- www.esteelauder.nl×3
- js.sentry-cdn.com×2
- www.esteelauder.at×2
- www.esteelauder.be×2
- www.esteelauder.ch×2
- www.esteelauder.com×2
- www.esteelauder.com.hk×2
- app.esteelauder.com.cn×1
- assets.sdcdn.io×1
- emea.sdapi.io×1
- fr.esteelauder.ca×1
- ui.powerreviews.com×1
- www.esteelauder.ca×1
- www.esteelauder.cl×1
- www.esteelauder.co.id×1
- www.esteelauder.co.il×1
- www.esteelauder.co.kr×1
- www.esteelauder.co.nz×1
- www.esteelauder.co.th×1
- www.esteelauder.co.za×1
- www.esteelauder.com.ar×1
- www.esteelauder.com.au×1
- www.esteelauder.com.br×1
- www.esteelauder.com.co×1
- www.esteelauder.com.gt×1
- www.esteelauder.com.mx×1
- www.esteelauder.com.pa×1
- www.esteelauder.com.pe×1
- www.esteelauder.com.ph×1
Social
DNS records live
- NS
-
- ns01.elcompanies.com
- ns02.elcompanies.com
- ns03.elcompanies.com
- MX
-
- 10 mail.global.sprint.com
- TXT
-
Show 10 TXT records
rvssj2f0k18qjzv3nwy0nwthhw0h1l2b985218488-295924972facebook-domain-verification=thnbku0lm1mntkko11heiz5auyv4dogoogle-site-verification=5YI6tR0Z-2uBaQXxOdPqUasfcEBb3yK8SAxAfzFEX6Mgoogle-site-verification=C6-ysNfF6TF4FP8vqW21AuYDgLMrVWr3ANrAvS5Kn04google-site-verification=DdVcz5ut1oV0w4TlJFdi8dUwvpn8Re8VEwUeIilkGaUgoogle-site-verification=RAQwecSWwK0UdrUM1fZctRnHGe2Uf-zdMNMls6LdhYcgoogle-site-verification=fZyD3pGuzVQ6TFKPFC7CGWdAtzPvqripvZp9Z5ngw08google-site-verification=zIKhv3FV_EzLqYMoiXxiJUFE19cKdCRGInk1ULw84G0nh9lwtdr732wz0zvglsy55p527b3vpfc
Email authentication strong
- SPF
-
v=spf1 ip4:207.82.108.152/32 include:spf-001a2001.pphosted.com include:spf.protection.outlook.com include:spf.esteeonline.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 82 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' *.google.com *.googleusercontent.com- strict-transport-security
max-age=31536000 ; includeSubDomains ; preload