hellotushy.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Shopify
- Analytics
-
- Google Analytics
Third-party hosts loaded (19)
- cdn.shopify.com×25
- assets.visually.io×4
- cdn-static.okendo.io×2
- live.visually-io.com×2
- sdk.helloextend.com×2
- shop.app×2
- www.google-analytics.com×2
- analytics.ahrefs.com×1
- api.config-security.com×1
- c.albss.com×1
- conf.config-security.com×1
- d3hw6dc1ow8pp2.cloudfront.net×1
- monorail-edge.shopifysvc.com×1
- play.gotolstoy.com×1
- public.getfondue.com×1
- static.klaviyo.com×1
- surveys.okendo.io×1
- tushyme.myshopify.com×1
- widget.gotolstoy.com×1
Social
Contact
- Phone
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2016-04-29
- Expires
- 2027-04-29 344 days left
- Updated
- 2026-04-30
- Name servers
-
- ns27.domaincontrol.com
- ns28.domaincontrol.com
DNS records live
- NS
-
- ns27.domaincontrol.com
- ns28.domaincontrol.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 30 alt2.aspmx.l.google.com
- 40 aspmx2.googlemail.com
- 50 aspmx3.googlemail.com
- TXT
-
Show 6 TXT records
google-site-verification=OXkuIHWjh34POKoqfL9nI4NiCge2ZOEjZ3UF2fpJ834google-site-verification=YXdvTpIiYLiwQ-ZVloOsuE0lduEl756IRRKcht-pCBkklaviyo-site-verification=atCGRVfacebook-domain-verification=r39cbkc8fss20u88zu97l5rglt74g3google-site-verification=_nnIjA_AcoZJLNlfnvKciISdlJqCWNMZt_jTOtdfDxwgoogle-site-verification=KVXUUIa1t0eL53wbtruVlPHdaRNEESELHLibbEjkqDk
Email authentication partial
- SPF
-
v=spf1 include:shops.shopify.com include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc-reports@hellotushy.compolicy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzjplS7BfFMgPgydlv3E7h+e9wHuKj47fOG5Z8xVqNM6r4SveFvu5/+zDnfYUMTWyQ8mrDpl4nBLKvB68Ns… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvjR837r36QVbbcTEQS+DmHpalWM/qccgtDmwg9eI4J9rdIZxsom4tND8a/DvZtZG5Qd+SCEuZuUfiIw2M0…
selectors probed - s1:
Certificate (current)
E8
Expires in 41 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
block-all-mixed-content; frame-ancestors *; upgrade-insecure-requests;- strict-transport-security
max-age=7889238
Links to (12)
- apple.com×1
- aspireiq.com×1
- buildwithtoki.com×1
- extend.com×1
- faire.com×1
- instagram.com×1
- loopreturns.com×1
- monday.com×1
- threads.net×1
- tiktok.com×1
- twitter.com×1
- youtube.com×1