heywoodhill.com

.com crawl

First seen 2026-04-15 · Last seen 2026-05-15 · ok HTTP/1.1 200 1395 ms crawled 2026-05-10

IE · 54.195.14.107 · AS16509 Amazon.com, Inc.

Reputation 100/100

sector other type homepage

HTML metadata

Title
Heywood Hill - The Bookshop at 10 Curzon Street, Mayfair
Description
Situated in the heart of Mayfair in London, Heywood Hill bookshop has been selling old, new and antiquarian books since 1936.
Language
en-GB
Canonical
https://www.heywoodhill.com

Open Graph

url
https://www.heywoodhill.com
title
Heywood Hill - The Bookshop at 10 Curzon Street, Mayfair
site name
Heywood Hill
description
The Bookshop at 10 Curzon Street, Mayfair, London.

Technology

Server
Microsoft-IIS
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (2)

  • fonts.googleapis.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

Registration

Registrar
IONOS SE
Created
2002-11-28
Expires
2026-11-28 191 days left
Updated
2025-10-29
Name servers
  • ns-1229.awsdns-25.org
  • ns-1862.awsdns-40.co.uk
  • ns-20.awsdns-02.com
  • ns-995.awsdns-60.net

DNS records live

NS
  • ns-1229.awsdns-25.org
  • ns-1862.awsdns-40.co.uk
  • ns-20.awsdns-02.com
  • ns-995.awsdns-60.net
MX
  • 0 heywoodhill-com.mail.protection.outlook.com

Email authentication strong

SPF
v=spf1 include:spf.protection.outlook.com include:_spf.createsend.com include:amazonses.com -all
strict (-all)
DMARC
v=DMARC1; p=reject;
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6G1FqrLyuORihw+ttzjckLs77eK4qJFLkuMsbA4/M/AxDueQ92MGhQFTbqttEjYkJqGLqlXBnH4HWwj4Byr…
selectors probed

Certificate (current)

Amazon RSA 2048 M04
from 2026-03-16 to 2026-09-30
Expires in 132 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.heywoodhill.com

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https: 'self'; connect-src https: wss: 'self'; font-src https: data: 'self'; frame-src 'self' https:; img-src https: data: 'self'; manifest-src https: 'self'; media-src https: 'self'; object-src 'none'; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline' 'self'; block-all-mixed-content; upgrade-insecure-requests; base-uri 'self';
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (2)