glossier.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Shopify
- Cookie consent
-
- OneTrust
Third-party hosts loaded (9)
- glossier-prod.imgix.net×18
- shop.app×2
- static.klaviyo.com×2
- assets.findation.com×1
- cdn.cookielaw.org×1
- cdn.optimizely.com×1
- config.gorgias.chat×1
- monorail-edge.shopifysvc.com×1
- onsite.joinground.com×1
Social
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 2012-09-24
- Expires
- 2026-09-24 128 days left
- Updated
- 2025-09-20
- Name servers
-
- jocelyn.ns.cloudflare.com
- norman.ns.cloudflare.com
DNS records live
- NS
-
- jocelyn.ns.cloudflare.com
- norman.ns.cloudflare.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
Show 24 TXT records
google-site-verification=IA5DZtg96rCQKVG26WV8j71irx8oyzHunpuYHoDncH4docusign=a92596d5-3a0b-4e53-b0d2-ecdfc090f6e9miro-verification=3e45756912d56d2e900634b4595dce1d6b7c2ff5amazonses:awBV5EM6W53p2/Xbg80uJ29zurZnGsMMJcLLLp6vUcY=google-site-verification=OFanMuGGmxbiQq2z4ysO4tdx2oMlVww21TGqOxI1750segment-site-verification=Spvd0xOkdgImbIGm3qFsnAlWYSe5VOSMgoogle-site-verification=V7tdGaaSh1KhOBoPS3KxWBSGTrb-kvva2Pi3Sf_KbuEgoogle-site-verification=rxzr5X3kOWcWXZ7pIfdiDSJTEUTWWY7ZNK0WENiZw40miro-verification=404cbf49b62824166e22b51b43b8a2525b5187a6onetrust-domain-verification=0ca018c3749d42bfb07250b87485d26cZOOM_verify_Zq39Zk_eQ_CPF75oAJOx4Astripe-verification=de5a0a999cba25aff482c390a6734885156463fb1e41045b8845016bc941e611klaviyo-site-verification=Sn6eFZgoogle-site-verification=MDrH2tc0AZu243TmQXE_Q99pcH0BPyLHKg-KolyEvw0stripe-verification=303ed2b7936a19cfa85a0df4455d323a4fca143eb2858d13adbcbecdd91da462jamf-site-verification=9lGMKRyd1dJT7FAFPmZxbgmonday-com-verification=79QHeajTu29O30o3fPua3jFjXEyZvMsyoZxZwehYUK8dropbox-domain-verification=blqrddqr7y8zSUPXKUABTshopify-verification-code=jmB03paWI8RHD9zzgcOEelizxhdn7Lgoogle-site-verification=_fQ4cuLrIAwed7medWswOf-pH_3wWxYMQcc-3XmhQs4apple-domain-verification=JYDlMr06cbovHzpKatlassian-domain-verification=9VPry9H7DUK/pyM/seOn2oYh7YZVeTm3eTjhT/lKpZLc3imKjD8FrT8D1UMzldywgoogle-site-verification=SAR6LwagmTqwph8i1rUHK-L-DXcONCPn2wSt1P0Auqw
Email authentication strong
- SPF
-
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.emailpolicy: reject (enforced) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAgRUIX6bpGix0IQcX3slks5TTHRvGz6RLMiePX37It+vrSSFVs5bI0eJAqd9AN5ZuyFG4MNwx+5fauo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5CPjIwVH/jfTIoGFFFpyMoeeXZqrM4hma7/Kt5OjTjWA02AcFZO+rsSKUQnzASg3slpEavnfJFet6ZeJJO… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDpDCE+FicPuc28f0mppTrjpIHMXo2RQw3wFWU/R5xn657Frh4zF3XSCVkin4R9ZgxUAS/TDQwC5wLf3Y7EmuQZtZ…
selectors probed - google:
Certificate (current)
E8
Expires in 43 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;- strict-transport-security
max-age=7889238