oreo.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Shopify
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- cdn.shopify.com×119
- images.ctfassets.net×42
- fonts.googleapis.com×1
- fonts.gstatic.com×1
- shop.app×1
Registration
- Registrar
- CSC Corporate Domains, Inc.
- Created
- 1996-12-18
- Expires
- 2026-12-17 211 days left
- Updated
- 2025-12-14
- Name servers
-
- dns1.cscdns.net
- dns2.cscdns.net
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 10 mx1.emailsrvr.com
- 20 mx2.emailsrvr.com
- TXT
-
Show 5 TXT records
google-site-verification=6Gw4TDMtU4FC6CLS_eK58h-zugYr8sAx9AHLKQhvDCMgoogle-site-verification=9Weo8vBjYhHhFJrM_JQEh5KueakDKmbJY6OuvJoVK3ogoogle-site-verification=HatPDB_pZzLYsBbrOhhevYA84gHxn1qBvs_Qef7Fhioklaviyo-site-verification=U5Rzxmosfsitecore-146650-cd.azurewebsites.net
Email authentication strong
- SPF
-
v=spf1 include:emailsrvr.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src 'self' 'nonce-792936567f100840eb53ff1c453b42f4' https://cdn.shopify.com https://shopify.com; frame-ancestors 'self' app.contentful.com *.googletagmanager.com oreo.com *.oreo.com; style-src privacyportalde-cdn.onetrust.com mondelez.review.eprize.com hello.myfonts.net http://c.lytics.io *.doogma.com s3-us-west-2.amazonaws.com *.click2cart.com click2cart.co *.click2cart.co maxcdn.bootstrapcdn.com *.audioeye.com *.lytics.io *.bazaarvoice.com display.ugc.bazaarvoice.com *.googletagmanager.com googletagmanager.com tagmanager.google.com fonts.googleapis.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src 'self' tr.snapchat.com tr6.snapchat.com graphql.contentful.com *.prod.uidapi.com prod.uidapi.com insight.adsrvr.org ct.pinterest.com s.pinimg.com cdn.growthbook.io s.amazon-adsystem.com c.amazon-adsystem.com ara.paa-reporting-advertising.amazon widget.euw1.chat.pega.digital wss://engine.euw1.chat.pega.digital pega-chat-attachments-euw1.s3.eu-west-1.ama- strict-transport-security
max-age=31536000