moosetoys.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- images.contentstack.io×73
- cdn-cookieyes.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Key-Systems GmbH
- Created
- 1996-05-30
- Expires
- 2027-05-29 373 days left
- Updated
- 2025-11-27
- Name servers
-
- clyde.ns.cloudflare.com
- megan.ns.cloudflare.com
DNS records live
- NS
-
- clyde.ns.cloudflare.com
- megan.ns.cloudflare.com
- MX
-
- 10 au-smtp-inbound-1.mimecast.com
- 20 au-smtp-inbound-2.mimecast.com
- TXT
-
Show 7 TXT records
vsktj8mclmgt4vm6nhrbebn4dq.0ed1fe018a13b03fb3eeb64947ad7daf012b0ebdad2f33cd94-7f8f-4a0d-8228-2c39c00384d1MS=747BD3CBA3FB610D5615DB7180651D8CB09DE5BBadobe-sign-verification=5b37806453d36d89fed40c04b066c0dejsbrsBBhktvs0qfqah87cvidosmj618tn7.
- Verified for
-
- Anthropic
- Apple
- Microsoft 365
- Slack
- Smartsheet
Email authentication strong
- SPF
-
v=spf1 include:au._netblocks.mimecast.com include:spf.protection.outlook.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:100e9062d3fe037@rep.dmarcanalyzer.com,mailto:f4803d997abb4704a55a8a3df7e14fc7@dmarc-reports.cloudflare.net; ruf=mailto:100e9062d3fe037@for.dmarcanalyzer.com; fo=1;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCXUP/mYAfMbWilFhknmYO7T9SgzzRah2x5g5b10yvqG3u4ufd4fJxkSzWuwRfMhRUmt2yL2gI5A8nLznMApy… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9k5jAur2JidNpEStmFboS1qSk4esg+rnVOA3/ExMCKbphpLF8ut6xFZ7W3GYmKnGngKo28nYxJovdLz4cBT… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 43 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
microphone=(), camera=(), geolocation=(), payment=()- x-content-type-options
nosniff- content-security-policy
default-src 'self';frame-src 'self' ct.pinterest.com *.youtube.com www.tiktok.com viewer.jig.space www.google.com app.marker.io *.freshchat.com;frame-ancestors 'self' ;img-src * data: w3.org/svg/2000;media-src youtube.com cdn.userway.com assets.contentstack.io;script-src 'self' 'unsafe-eval' 'unsafe-inline' ;script-src-elem 'self' 'unsafe-inline' s.pinimg.com widget.freshworks.com ct.pinterest.com *.youtube.com *.marker.io *.channelsight.com *.visualstudio.com *.azure.com *.googleapis.com *.googletagmanager.com cdn-cookieyes.com *.clarity.ms connect.facebook.net www.google.com www.gstatic.com *.freshchat.com fw-cdn.com acsbapp.com analytics.tiktok.com www.redditstatic.com;style-src 'self' 'unsafe-inline' widget.freshworks.com;style-src-elem 'self' 'unsafe-inline' assets.contentstack.io fonts.googleapis.com widget.freshworks.com cdn.channelsight.com p.typekit.net *.onetrust.com *.klaviyo.com *.freshchat.com use.typekit.net;connect-src 'self' ct.pinterest.com widget.freshworks.com *.- strict-transport-security
max-age=63072000- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin
Links to (7)
- facebook.com×2
- goodcompany.org×2
- instagram.com×2
- privo.com×2
- taleo.net×2
- tiktok.com×2
- youtube.com×2