niveausa.com

.com crawl

First seen 2026-04-17 · Last seen 2026-05-12 · ok HTTP/1.1 200 1202 ms crawled 2026-05-12

US · 104.210.154.101 · AS8075 Microsoft Corporation

Reputation 100/100

Classifying

HTML metadata

Title
Home | NIVEA
Description
Welcome to the NIVEA Website! We offer you great tips and exciting opportunities related to the loved skincare products by NIVEA.
Language
en-US
Canonical
https://www.niveausa.com/

Open Graph

url
https://www.niveausa.com/
title
Home | NIVEA
description
Welcome to the NIVEA Website! We offer you great tips and exciting opportunities related to the loved skincare products by NIVEA.

Technology

CDN
Azure Front Door
CMS
Next.js

Third-party hosts loaded (2)

  • assets.beiersdorf.com×2
  • tm-eu.beiersdorf.com×1

Social

Registration

Registrar
CSC Corporate Domains, Inc.
Created
1999-09-14
Expires
2026-09-14 117 days left
Updated
2025-09-10
Name servers
  • ns1.netnames.net
  • ns2.netnames.net
  • ns5.netnames.net
  • ns6.netnames.net

DNS records live

NS
  • ns1.netnames.net
  • ns2.netnames.net
  • ns5.netnames.net
  • ns6.netnames.net
MX
  • 20 niveausa-com.mail.protection.outlook.com
TXT
  • google-site-verification=-Kupo1lVz-PNTudsGyYfR0YJU9MFsrkrChpvNAwo-CY
  • google-site-verification=Fay-3oBdbJSpoxK6AaaJmdSs9bq8hzouRP9Ry58GktM
  • MS=ms28379003

Email authentication strong

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; fo=1; rua=mailto:beiersdorf@rua.agari.com; ruf=mailto:beiersdorf@ruf.agari.com
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-07 to 2026-07-06
Expires in 47 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.niveausa.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • cross-origin-opener-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src https: 'unsafe-inline' 'unsafe-eval'; img-src 'self' blob: data: https:; font-src 'self' data: https:; worker-src blob:
strict-transport-security
max-age=31536000; includeSubDomains; preload
cross-origin-opener-policy
same-origin
cross-origin-resource-policy
same-origin

Links to (4)

Linked from (1)