nastygal.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (5)
- mediahub.debenhams.com×43
- mediahub.nastygal.co.uk×4
- 043f2fa08795.edge.sdk.awswaf.com×1
- www.googletagmanager.com×1
- www.nastygal.co.uk×1
Social
Registration
- Registrar
- EuroDNS S.A.
- Created
- 2004-03-29
- Expires
- 2030-03-29 1409 days left
- Updated
- 2024-01-24
- Name servers
-
- ns-1131.awsdns-13.org
- ns-1652.awsdns-14.co.uk
- ns-409.awsdns-51.com
- ns-667.awsdns-19.net
DNS records live
- NS
-
- ns-1131.awsdns-13.org
- ns-1652.awsdns-14.co.uk
- ns-409.awsdns-51.com
- ns-667.awsdns-19.net
- MX
-
- 0 nastygal-com.mail.protection.outlook.com
- TXT
-
Show 18 TXT records
google-site-verification=ztORAbvwLrWPbmnhlaTTFU6MBldz1RFY1qEUQpXVGIoknowbe4-site-verification=36922c47a3ee3ce6a1efae204962c43a_globalsign-domain-verification=bXbEQA9gnDINpNo0Qknw32chwcYMGSts6n--4bpV4Jgoogle-site-verification=n5n51WhNVkUv0UEQqPUi8T90llZhsyCzWDFMCvPPk8IValidity-Domain-Verification=tnYyPeQ7/DFcARgWOwDs82R6Z3nFz9=0ed1fe018a3ee6170aed28431ab85db1af1d41ed02google-site-verification=b7jsLAp5ytmow6cz-NYjXiG5_1XQh3m3Kltm0_YFqAA_globalsign-domain-verification=mx9VP6ssw3XkHz5uhtr3fvMAV0zIaWMTSNQk1eOJiGahrefs-site-verification_0a04b7695dbee89463dfb25f218ecfba0cf2eeb7d693eb6c415e6c92ab7c72f6_globalsign-domain-verification=hQ4-5C7iaN2bbWkZm5oLu1x3lRsb-cju5XQTfNUsrQgoogle-site-verification=_pdJG6iq81xAOQ1tiT28VGsIJM25Lw6ZiigkcKjny8sklaviyo-site-verification=R2yHea_globalsign-domain-verification=4UKUjDCiJjhC3wFSd9NSrdMYHFwhk2EfbSc7VfeC_Cadobe-idp-site-verification=805380471ebc6fc5909ac31fd1a5c670723bd84b921237c8d150a3d89676ea6fgoogle-site-verification=O5Ix80RpktTT5-r9owHpXM2YAeu3vQjKjC8YQEaDMUEfacebook-domain-verification=vq353oczq9mv5nc9ncs07bc0nomqq2MS=ms23478193google-site-verification=vHhYAQRn7zWi-RN3LHvmJ6AgqhqMIkE_IEiXA_TAzJE
Email authentication strong
- SPF
-
v=spf1 ip4:151.106.142.75 include:spf.protection.outlook.com include:mailgun.org a:production.us1.boohoo.demandware.net include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:a.ipa9nhg4@sdmarc.net,mailto:f4f6060ce2ec750@rep.dmarcanalyzer.compolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCnaX8i4iQNgfwSJp3QXZ43q1S0rwJNLPP4/Ydy7FaUSVxDzJRki7HaCD30pPyDY51zBxlNfzagvmjEJZZ02+… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed - selector1:
Certificate (current)
R12
Expires in 58 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src data: * blob: *; media-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; child-src *; frame-ancestors *; connect-src *; font-src data: *; worker-src blob:;- strict-transport-security
max-age=31536000; includeSubDomains