hilma.co

.co crawl

First seen 2026-04-20 · Last seen 2026-05-14 · ok HTTP/1.1 200 991 ms crawled 2026-05-14

CA · 23.227.38.32 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Hilma -- Natural Remedies, Backed By Science
Description
The medicine cabinet staples that everyone needs. Natural remedies that are doctor approved, with clinically substantiated ingredients.
Language
en
Canonical
https://www.hilma.co/

Technology

CDN
Cloudflare
CMS
Shopify
Analytics
  • Google Tag Manager
Third-party hosts loaded (9)
  • cdn.jsdelivr.net×9
  • shop.app×2
  • static.klaviyo.com×2
  • apps.bazaarvoice.com×1
  • cdn.shopify.com×1
  • cookie-cdn.cookiepro.com×1
  • monorail-edge.shopifysvc.com×1
  • static.zdassets.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Address
77 Sands St., 6th Floor, 11201, Brooklyn, New York, United States

DNS records live

NS
  • ns09.domaincontrol.com
  • ns10.domaincontrol.com
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 7 TXT records
  • google-site-verification=wVCeayS-eoSEPRYgbQhXgSh3wEOZhHvAT42UNQ5wA4U
  • google-site-verification=hyqnFPbWYXa-NcLs-atS4BoxZckHP_MHKRckLUWIbd4
  • google-site-verification=LBjL5PBOrCEgv52DLIJJLsrXTGUbXQuzlAc9_C6Rcoo
  • google-site-verification=Tg2MY5_nUggKqNjhrA_CHdKQ0DbhiQS15a60CVttjqE
  • klaviyo-site-verification=HV2Nda
  • google-site-verification=ZKcfJepM2_ACKdNdPjFUia5ZyO_WXeI_T956JmLUmBM
  • facebook-domain-verification=5lvcraruu35fl2np5hqtcu0z72f9yn

Email authentication partial

SPF
v=spf1 include:_spf.google.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

E7
from 2026-03-31 to 2026-06-29
Expires in 41 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.hilma.co/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • short HSTS max-age
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
strict-transport-security
max-age=7889238

Links to (5)

Linked from (1)