iguanas.co.uk

.uk crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 958 ms crawled 2026-05-30

US · 104.20.47.39 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
The Best Mexican Restaurant & Cocktail Bar | Las Iguanas | Las Iguanas
Description
Join us for all day cocktail Happy Hour, Bottomless Brunch and Mexican & South American dishes including plenty of vegan & vegetarian options.
Language
en
Canonical
https://www.iguanas.co.uk

Open Graph

title
The Best Mexican Restaurant & Cocktail Bar | Las Iguanas | Las Iguanas
site name
Las Iguanas
description
Join us for all day cocktail Happy Hour, Bottomless Brunch and Mexican & South American dishes including plenty of vegan & vegetarian options.

Technology

CDN
Cloudflare
CMS
Nuxt
jQuery
3.6.0
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • images.ctfassets.net×54
  • cdnjs.cloudflare.com×1
  • www.googletagmanager.com×1

Social

DNS records live

NS
  • nadia.ns.cloudflare.com
  • sam.ns.cloudflare.com
MX
  • 10 iguanas-co-uk.mail.protection.outlook.com
TXT
Show 7 TXT records
  • iguanaspeople.co.uk
  • savo77caam8kpmq6doqtbvoid1
  • 0ed1fe018aaebfa2229bf849a1affe73
  • 5ci444sb2ukrtuu38t4aqnmjqi
  • 5k31ok93spa4gv466u3ic7tl8v
  • SmUQV6BkHmsaKwFW0/GVTxiVb/mRHZIy7nFEcZnJQqI/hRIt/dUANwiib7h7khGEysSmIqGtVWQczKAlmwHhjQ==
  • ckrnjdmkqlp7bt9k9h8qf54p3e
Verified for
  • Google

Email authentication strong

SPF
v=spf1 include:spf.mailjet.com include:spf.protection.outlook.com include:shops.shopify.com include:mailer.shopifyemail.com include:txdltd.co.uk -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email;
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6gbzRQzGYK0XEuxBhhAngtKjW6rdjg5eO6ffc/oUlscfSidTQhW/UJ+6cR2DAqVbao/GeSt5NLhOho…
selectors probed

Certificate (current)

E7
from 2026-05-02 to 2026-07-31
Expires in 61 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.iguanas.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
camera=(), microphone=(self "https://web.lovebite.app"), geolocation=(self)
x-content-type-options
nosniff
content-security-policy
style-src 'self' 'unsafe-inline' *.googleapis.com *.google-analytics.com *.gstatic.com *.tenkites.com tkmenus.com partners.designmynight.com atlas.microsoft.com *.cdn-cookieyes.com *.liveres.co.uk *.braintreegateway.com *.googleads cdn.co-buying.com https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.13/css/intlTelInput.css *.instagram.com use.typekit.net https://use.typekit.net/wca6end.css https://p.typekit.net https://p.typekit.net/p.css; font-src 'self' data: *.googleapis.com *.google-analytics.com *.gstatic.com *.tenkites.com tkmenus.com atlas.microsoft.com *.liveres.co.uk *.braintreegateway.com *.googleads cdn.co-buying.com *.instagram.com use.typekit.net; script-src 'self' 'self' data: 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.googleapis.com *.hotjar.com cdn-cookieyes.com *.tiktok.com *.licdn.com *.ads-twitter.com *.twitter.com *.bing.com *.facebook.net *.google.com *.gstatic.com *.google-analytics.com *.exponea.com *.tenkites.com tkmenus.com *.braintreegatewa
strict-transport-security
max-age=31536000; preload

Links to (4)

Linked from (1)