liberator.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (8)
- fonts.googleapis.com×7
- cdn-widgetsrepository.yotpo.com×1
- cdn.userway.org×1
- fonts.gstatic.com×1
- script.crazyegg.com×1
- static.elfsight.com×1
- www.googletagmanager.com×1
- www.youtube.com×1
Social
Contact
- Phone
Registration
- Registrar
- PDR Ltd. d/b/a PublicDomainRegistry.com
- Created
- 1996-09-13
- Expires
- 2026-09-12 115 days left
- Updated
- 2021-07-14
- Name servers
-
- ns1.sectigoweb.com
- ns2.sectigoweb.com
- ns3.sectigoweb.com
- ns4.sectigoweb.com
DNS records
- MX
-
- 1 smtp.google.com
- TXT
-
Show 5 TXT records
tmes=b0dc48d09961927f000c4917170b7b0d_globalsign-domain-verification=G8x6GHbThIdz1cDp0Qvgzcid-i7zJnKh446wl35a6Wglobalsign-domain-verification=0939dac5d2f3ef9db8ddd5e95cf4de4fglobalsign-domain-verification=dcbd6d7de13b9e11ea70a84dca8ce167openai-domain-verification=dv-rnmTjtlnuDnbSoJpyz5PGfLc
Email authentication strong
- SPF
-
v=spf1 a mx ip4:166.78.224.184 ip4:12.71.93.2 include:_spf.google.com include:servers.mcsv.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@liberator.com;pct=100; adkim=r; aspf=rpolicy: quarantine - DKIM
-
Show 4 DKIM selectors
- google:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+xN7mp/9j931fVbfm4fcDqHRs25dmyDDr2Xpl8isxmZ4UqVc+TCGyXHvisMjTRGkXTW/GViaUknrJT… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3xWsVB6syk4wrcZz/YDOdvVThmmKGHoUdSdEt11rCCFeqtyNCFfcRXwM9UHq7kLfzcaUc8Am8xzqkqOkm0… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvrd+2sCiBA5KzTnzzdR/f0xcMWHE5DROBVSSQ9aqOJNAouVEi/6RfiIiyNtjnIKeqjyoBiSjLi09Skd6yF…
selectors probed - google:
Certificate (current)
E8
Expires in 57 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' www.youtube.com www.dwin1.com acsbapp.com *.yotpo.com cdn.listrakbi.com www.googletagmanager.com www.google-analytics.com www.redditstatic.com *.listrakbi.com *.cloudfront.net checkout-sdk.sezzle.com static-na.payments-amazon.com www.google.com www.recaptcha.net www.gstatic.com admin.liberator.com connect.facebook.net s.pinimg.com www.googleadservices.com widget.surveymonkey.com *.adroll.com *.pinimg.com googleads.g.doubleclick.net ajax.googleapis.com assets.adobedtm.com web-sdk.aptrinsic.com apis.google.com cdn.jsdelivr.net *.tryinteract.com *.braintree.com lex.33across.com *.google-analytics.com *.payments-amazon.com translate.google.com *.googleapis.com *.paypal.com *.payflow.com *.sezzle.com *.freshdesk.com *.googlesyndication.com chat.freshdesk.com static.fliphtml5.com *.hotjar.com *.listrak.com *.paypalobjects.com js.braintreegateway.com www.liberator.com blob: widget.sezzle.com pay.google.com static.elfsight.com js-- strict-transport-security
max-age=31557600- content-security-policy-report-only
font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.yotpo.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com