headout.com

.com crawl

First seen 2026-04-20 · Last seen 2026-05-19 · ok HTTP/1.1 200 5122 ms crawled 2026-05-14

US · 18.165.122.125 · AS16509 Amazon.com, Inc.

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
Headout: Things To Do, Attractions, Tours, Events & Experiences
Description
Explore the world's best experiences - from expert-led tours and incredible landmarks to activities and events. Book tickets at the lowest prices and best deals.
Language
en
Canonical
https://www.headout.com/
Translations
  • de
  • en
  • es
  • fr
  • it
  • nl
  • pl
  • pt
  • ru

Open Graph

url
http://www.headout.com/
title
Headout: Things To Do, Attractions, Tours, Events & Experiences
video
https://cdn-imgix-open.headout.com/opengraph/headout.mp4
image:url
https://cdn-imgix-open.headout.com/flaps/non-city-specific/desktop/headout-default-banner-desktop-1.png?auto=compress&w=768&h=319&fit=min
video:url
https://cdn-imgix-open.headout.com/opengraph/headout.mp4
video:type
video/mp4
video:secure url
https://cdn-imgix-open.headout.com/opengraph/headout.mp4

Technology

CDN
Amazon CloudFront
Server
istio-envoy
CMS
Next.js
Analytics
  • Google Tag Manager
Fonts
  • Adobe Fonts

Third-party hosts loaded (4)

  • use.typekit.net×6
  • 899327000×1
  • com.tourlandish.chronos×1
  • www.googletagmanager.com×1

Social

Contact

Email
Address
82 Nassau St #60351, 10038, New York City, NY, USA

Registration

Registrar
GoDaddy.com, LLC
Created
1996-11-04
Expires
2032-11-03 2359 days left
Updated
2023-10-31
Name servers
  • ns-1087.awsdns-07.org
  • ns-1784.awsdns-31.co.uk
  • ns-330.awsdns-41.com
  • ns-978.awsdns-58.net

DNS records live

NS
  • ns-1087.awsdns-07.org
  • ns-1784.awsdns-31.co.uk
  • ns-330.awsdns-41.com
  • ns-978.awsdns-58.net
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 25 TXT records
  • google-site-verification=DOb004kU94d_rTw7PdBbP6sDFZeazna2-xTnbAi5V_g
  • firebase=headout-a7023
  • google-site-verification=FKlSPjuyZm4DWDU4Vw39W8N5BHtul8G6WZ-_wbjTKKU
  • apple-domain-verification=LnaaC9s9fzA-MWWOVBuA5LoIKek-MI85U632D5fbsnM
  • apple-domain-verification=KrWQwtQT4t7tNp4YeUjXvvFkAMAb7we60j-wd_jpJsM
  • apple-domain-verification=3_CL499tsrvfjyiBhHKuF1quVru6oGCEU1xBNxVastY
  • google-site-verification=jd-lsCqiqrI04_M8c1idb8gV0QzD7NP2ZfaovY-PkLw
  • google-site-verification=zKETnZreJg4TPMDRTA3soePirsP3KVV_qIGX9ZPOu90
  • stytch_verification_dns=precious-match-0137
  • google-site-verification=XaZUIFSfTcbqCMBs33mi8Qqb00ngpWSX1MoMflxxXaA
  • google-site-verification=iVD-F334jWt9NCjbm504ZLNHaifDYENEqTuhy_u9N9E
  • 53835
  • google-site-verification=JhRWN6TG2ui_wos85btdjAGOVNdDAF87ygWTKS2_sG0
  • apple-domain-verification=I9mUaV74mkJhxj1nhA63zZG5losqBe8utsIvvxkK0QQ
  • google-site-verification=98ez0X1Qjm283knwDjJzyBLfdK8HZSDwhC_gfokKK3U
  • sending_domain1053543=fc01763e160fc9c55ae0db96dd48de063d2d9938bfb29f6610ea2e101370a908
  • tiktok-developers-site-verification=cSxFjnYKPqeEvjHytwwGT5NpIUxyYHMj
  • apple-domain-verification=3Hm4rUbKruRZt5Ewms8hlRSkx8qCJvzEEV_hgpXF-IU
  • yandex-verification=45ebd1118f5667b4
  • google-site-verification=fLGkCERW2fzYTVTsHjhzc6B0DQKLzZ-euFToHsqQhPI
  • google-site-verification=-vRkhwgEWjixtLHugzAvgfWSUh_3zTk4g-EkefFHXf8
  • google-site-verification=J2GNL6P00fkWEqc_wQ1yViCdWMb4DvrHQlpdbfthdH4
  • google-site-verification=LBGBhOt8k0YKuupNhtFopOOfkL5XJhNpuzBaFQqajSM
  • apple-domain-verification=o4EK78AFjSGaPdR_IOa7Ayjwv9yCtPPkuE0II2AmhUY
  • apple-domain-verification=JMfWDk6saKglAaRc2vgSA7Y59qW7aoXztxRqEZQxLPo

Email authentication strong

SPF
v=spf1 include:spf0.headout.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc-reports@headout.com, mailto:support@headout.com, mailto:dmarc_agg@vali.email
policy: reject (enforced)
DKIM
Show 5 DKIM selectors
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmMIAx1IiHUsl8D53ZlVnoGsrHvjvH46C1hmYHwuBpPn9aSKnsvz9XGgk8b3St1vt6DTJjfsrxk3rvY/AKbi…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7OZWHJ4xPMRTsbggzDGpzVTnS/x8ttA83Q0hQuuBSoFivtjGd3paGGyZFyQWSGSBds0whGBzZ5WRKhNp4…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9FydwofzjfW+LUMJcqKxs5rHZ8c4cdm0GQVvUVa6hm/KzyJXmtgsRjTzpEnEzfPk/yVjwBBgxD0jiye4CHU/Iir…
  • smtpapi: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed

Certificate (current)

Amazon RSA 2048 M04
from 2026-04-17 to 2026-11-01
Expires in 165 days

HTTP security headers

Header hygiene 30/100 Checked live page: https://www.headout.com/

findings
  • missing HSTS
  • missing Content Security Policy
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy

Links to (5)

Linked from (8)