leyaonline.com

.com crawl

First seen 2026-05-30 · Last seen 2026-05-31 · ok HTTP/1.1 200 1745 ms crawled 2026-05-31

US · 3.33.176.39 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
LeYa Online
Language
en
Canonical
https://leyaonline.com/pt/

Open Graph

url
https://leyaonline.com/pt/
title
LeYa Online
site name
LeYa Online
description
A livraria online das editoras do Grupo Leya: livros, ebooks, manuais escolares e livros de apoio escolar.

Technology

Server
nginx
Stack
PHP
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • www.googletagmanager.com×2
  • cdn.cookie-script.com×1
  • www.facebook.com×1

Social

Registration

Registrar
Network Solutions, LLC
Created
2012-04-19
Expires
2027-04-19 322 days left
Updated
2022-02-18
Name servers
  • ns-1455.awsdns-53.org
  • ns-1871.awsdns-41.co.uk
  • ns-36.awsdns-04.com
  • ns-933.awsdns-52.net

DNS records live

NS
  • ns-1455.awsdns-53.org
  • ns-1871.awsdns-41.co.uk
  • ns-36.awsdns-04.com
  • ns-933.awsdns-52.net
MX
  • 0 leyaonline-com.mail.protection.outlook.com
  • 10 mx02efa.leya.com
Verified for
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 ip4:195.246.239.0/24 ip4:195.246.238.0/24 include:spf.protection.outlook.com include:_spf.kmitd.com -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; pct=100; fo=0; rua=mailto:dmarc-reports@leya.com; ruf=mailto:leya@eu.cp-dmarc.com
policy: quarantine
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArK7gXqdvZkVoiFRSA3qM5KC0RTEWHdRHVHeUukZ5LVpvF5vZdgQyerFNI8B2i/zRV9Zq2BYEhIL0rB…
selectors probed

Certificate (current)

R12
from 2026-04-14 to 2026-07-13
Expires in 42 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://leyaonline.com/pt/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; img-src * 'self' data: https:; style-src https: 'unsafe-inline' 'unsafe-eval'
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (1)