levooil.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Shopify
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (19)
- cdn.shopify.com×13
- fonts.googleapis.com×5
- cdnjs.cloudflare.com×3
- fonts.gstatic.com×2
- shop.app×2
- aggle.net×1
- cdn-static.okendo.io×1
- cdn.intelligems.io×1
- cdn.rebuyengine.com×1
- fonts.shopifycdn.com×1
- monorail-edge.shopifysvc.com×1
- play.gotolstoy.com×1
- productreviews.shopifycdn.com×1
- shopify-init.blackcrow.ai×1
- static.klaviyo.com×1
- tag.simpli.fi×1
- widget.gotolstoy.com×1
- www.googletagmanager.com×1
- www.lightboxcdn.com×1
Social
Registration
- Registrar
- Squarespace Domains II LLC
- Created
- 2013-03-08
- Expires
- 2027-03-08 291 days left
- Updated
- 2026-02-21
- Name servers
-
- ns-cloud-d1.googledomains.com
- ns-cloud-d2.googledomains.com
- ns-cloud-d3.googledomains.com
- ns-cloud-d4.googledomains.com
DNS records live
- NS
-
- ns-cloud-d1.googledomains.com
- ns-cloud-d2.googledomains.com
- ns-cloud-d3.googledomains.com
- ns-cloud-d4.googledomains.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 7 TXT records
klaviyo-site-verification=MZ2BBNamazonses:qM1B1Ki+GyAPGbs0X7yrstpPxJH7ciW4TpdyFRS2Eok=MS=85032B354133038CCA44159AE2F22FB11174A227default._bimi.levooil.comv=BIMI1; l=https://cdn.shopify.com/s/files/1/1362/6597/t/109/assets/LEVO_Favicon_OilDroplet_Summer2020.svg;v=DMARC1; p=quarantine; rua=mailto:hello@levooil.com; ruf=mailto:daniel@thelimitlessagency.com; fo=1; sp=quarantine85032B354133038CCA44159AE2F22FB11174A227
- Verified for
-
- Ahrefs
- Meta
Email authentication strong
- SPF
-
v=spf1 +a +mx +ip4:173.254.104.26 include:_spf.google.com include:spf.gorgias.com include:klaviyo._spf.google.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:hello@levooil.com; ruf=mailto:daniel@thelimitlessagency.com; fo=1; sp=quarantinepolicy: quarantine · sp=quarantine - DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 37 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
block-all-mixed-content; frame-ancestors *; upgrade-insecure-requests;- strict-transport-security
max-age=7889238