merlins.com

.com crawl

First seen 2026-04-20 · Last seen 2026-05-14 · ok HTTP/1.1 200 5701 ms crawled 2026-05-14

US · 216.134.192.246 · AS13649 Flexential Colorado Corp.

Reputation 89/100 weak security headers dmarc monitor-only

Classifying

HTML metadata

Title
Merlins
Language
en

Technology

Server
Apache
Analytics
  • Google Tag Manager
Ads
  • Xandr
Third-party hosts loaded (8)
  • d134hm8d145rgp.cloudfront.net×19
  • www.googletagmanager.com×2
  • cdnjs.cloudflare.com×1
  • connect.podium.com×1
  • embed.shopgenie.io×1
  • maps.googleapis.com×1
  • secure.adnxs.com×1
  • www.google.com×1

Social

Registration

Registrar
GoDaddy Corporate Domains, LLC
Created
1995-12-21
Expires
2027-12-20 580 days left
Updated
2026-03-29
Name servers
  • ns1.brandsight-dns.com
  • ns1.brandsight-dns.net
  • ns2.brandsight-dns.com
  • ns2.brandsight-dns.net

DNS records live

NS
  • ns1.brandsight-dns.com
  • ns1.brandsight-dns.net
  • ns2.brandsight-dns.com
  • ns2.brandsight-dns.net
MX
  • 10 merlins-com.mail.protection.outlook.com
TXT
Show 5 TXT records
  • MS=ms71501763
  • knowbe4-site-verification=01aa39e642437e93568de77790b0f2ef
  • v=spf1include:spf.protection.outlook.cominclude:spf.mandrillapp.cominclude:sendgrid.net -all
  • atlassian-domain-verification=IweytGg70EEJaLMOSO6OeG88dL1kjEaY4PLjNUaJZOHFrJCdO2yYQJskbD0VviX+
  • MS=ms45092825

Email authentication partial

SPF
v=spf1include:spf.protection.outlook.cominclude:spf.mandrillapp.cominclude:sendgrid.net -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:dmarc@drivenbrands.uriports.com; ruf=mailto:dmarc@drivenbrands.uriports.com; fo=1:d:s
policy: none (monitoring only)
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAycewtIdK6HDNZ5k1cVxIzeG0zKiyvZRks+T123ZzNPhg9L9M4MCTNfhKA15Cp1PX+9zqEcAaMtzbbAdIx2…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC4VzEk4UYJS5qvZvMpy/bZdo04deeUS8mEkx4vaNfKjKPoAN9Js5oAHisfgVLdjkrcbyMhwcf+BrX/hVExfStrZ9…
selectors probed

Certificate (current)

E8
from 2026-04-12 to 2026-07-11
Expires in 53 days

HTTP security headers

Header hygiene 30/100 Checked live page: https://www.merlins.com

findings
  • missing HSTS
  • missing Content Security Policy
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy

Links to (9)

Linked from (1)