linnworks.net
HTML metadata
Technology
- CMS
- Gatsby
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2011-09-19
- Expires
- 2026-09-19 122 days left
- Updated
- 2025-08-15
- Name servers
-
- ns-1504.awsdns-60.org
- ns-1689.awsdns-19.co.uk
- ns-79.awsdns-09.com
- ns-866.awsdns-44.net
DNS records live
- NS
-
- ns-1504.awsdns-60.org
- ns-1689.awsdns-19.co.uk
- ns-79.awsdns-09.com
- ns-866.awsdns-44.net
- TXT
-
postman-domain-verification=e25cbf5d346f8433bd6415e795afbff8f510b9459bbc54659a2e045dd51b28cc8b963a37a69df007475d0f220e0a52477882032c45ca4c38631a67a25296b678google-site-verification=yDXiyxdoWcN6Z4gQiIa0HhOnP45eSXOEfX1R6EhJjbQ
Email authentication no MX
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=rejectpolicy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M03
Expires in 104 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=("https://www.youtube.com"), autoplay=("https://www.youtube.com"), camera=(), clipboard-write=("https://www.youtube.com"), display-capture=(), encrypted-media=("https://www.youtube.com"), fullscreen=("https://www.youtube.com"), geolocation=(), gyroscope=("https://www.youtube.com"), magnetometer=(), microphone=(), picture-in-picture=("https://www.youtube.com"), web-share=("https://www.youtube.com")- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; child-src 'self' https: http: data: blob:; connect-src 'self' https: http://localhost:* wss: data: blob:; default-src 'none'; font-src 'self' https: http://localhost:* http://themes.googleusercontent.com data:; form-action 'self'; frame-ancestors 'self' https://app.eu.pendo.io; frame-src 'self' https: http: data: blob:; img-src 'self' https: http: data: blob:; media-src 'self' https: data:; script-src 'self' https: http://localhost:* blob: 'unsafe-inline' 'unsafe-eval' 'report-sample'; style-src 'self' https: http: data: 'unsafe-inline' 'report-sample'; worker-src 'self' blob:- strict-transport-security
max-age=63072000; includeSubDomains