overstock.com
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
Third-party hosts loaded (2)
- ak1.ostkcdn.com×60
- g.3gl.net×1
Social
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 1999-02-11
- Expires
- 2027-02-11 268 days left
- Updated
- 2025-01-10
- Name servers
-
- dns1.p01.nsone.net
- dns2.p01.nsone.net
- dns3.p01.nsone.net
- dns4.p01.nsone.net
DNS records live
- NS
-
- dns1.p01.nsone.net
- dns2.p01.nsone.net
- dns3.p01.nsone.net
- dns4.p01.nsone.net
- MX
-
- 0 overstock-com.mail.protection.outlook.com
- TXT
-
Show 17 TXT records
google-site-verification=UUPHMXa2WH-c7Ys9XL_GPwPAkxNv30jPjL-9RIeUuQcgoogle-site-verification=sAwY-6V5arQLrN2vY7sPrzNHK5A5G9d9sY9Jgy7LrLUgoogle-site-verification=VrzafT6KoHLIM-B7JiT4dh2C-fGBTObm_Zo_X3WMYdk794a5440-2f7e-4290-a111-d760825bfeedgoogle-site-verification=hMfR3Z6ihuxLHC8UHB8dsH7_71t2r4SPrw3o1Qnpehoatlassian-domain-verification=RlWBXVhdSBLcKksNQLCSI0icckuVo55zfKultsMlgfj9lWcAIDx9N8v88Oozjav9google-site-verification=k5byGCYNNnSKN5QdbOmnB4QHHCzrw5qGrDvjpfZPjc8docker-verification=00f612b4-15a8-46ae-bf21-393a993c1b43_globalsign-domain-verification=EGXYWFCTQynvOf5IBle5NjMEbKo9PBQaeH9mnr_Fajglobalsign-domain-verification=51930d36897f77a8aa763ef9b730fc90google-site-verification=PLPmk5cozL_pVgYYV90K1_-sVH_QeS5NOQbJhdgQlH4google-site-verification=lwFhdI9C5N47saoU82L1IMs6aKWf2pcWgsVkFhMYJU8+bcd9BHkZzHoTMOHkZirO2Z0FzBmBxCVNUMvJL0oTEtOkQL2kGPDmmozPsq5PCWLs3ichMIz4+Zgn1W/FtA9Rw==_globalsign-domain-verification=NIyArddHtOpe5kb_pCFH5D_yiT5xVzEqeORSeRee0egoogle-site-verification=-R3F1JCZ-YdCBGCgpU8QnTO3UdaWpmgb78lbMuXeqroahrefs-site-verification_cea064a893366cd43a3c4062df9c8f11662ee73530c0c6f325d10aa92f0807c3f9ZtNknHxHL5abJ6sP4n
Email authentication strong
- SPF
-
v=spf1 ip4:65.116.112.0/21 ip4:173.241.144.0/20 ip4:52.8.140.255 ip4:54.164.132.26 ip4:35.169.47.31 ip4:18.217.82.134 include:spf.protection.outlook.com include:_spf.salesforce.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; rua=mailto:mioer-8438@rua.dmarc.emailanalyst.com,mailto:beyond23@us.cp-dmarc.com; ruf=mailto:beyond23@us.cp-dmarc.com; adkim=r; aspf=r; ri=86400; fo=1; pct=100policy: reject (enforced) · sp=reject - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwwkAZX9vmGioC1zq+F97uv7TMkvoNXLFUV76DSxzF2HI7mv7RsbSOHvnmxiXrnpoGeWDGWOVlFSLXY… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArR7Yf9uukOASyRMIVdp6l/j3riT3N9q7/TrLXugk4E196egLj0ij6jMTeIJ2ehkSJt5SRE0JARhDs8… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA+ELs45/6xFZS7pcguWN1xP0v/PI2c7iqKGJ8UHKmVx18RIk/NKV3SEZ0UAblQ5UDtG3UMbyxvCq4B7D6zy… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDxCD6cGIumV5GBa83UbmGfjCU3Z+a/r98tbrLHUmlyeAMUU29Ll4ggVeJN/O3/laUxTOFfnIkaCDP/GX7/z0iRTU…
selectors probed - selector1:
Certificate (current)
DigiCert Global G3 TLS ECC SHA384 2020 CA1
Expires in 254 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
upgrade-insecure-requests;default-src 'self' blob: 'unsafe-eval' 'unsafe-inline' *.akamaihd.net *.bedbathandbeyond.com *.cloudinary.com *.ostkcdn.com *.overstock.com *.swarmshop.com unpkg.com vercel.live apple.com applepay.cdn-apple.com *.bing.com *.bing.net *.braze.com *.clarity.ms *.facebook.net *.facebook.com *.google.com *.google.ca *.google.co.uk *.google.ie *.google.mx *.google-analytics.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.3gl.net *.newrelic.com *.nr-data.net *.appboycdn.com *.creativecdn.com *.doubleclick.net *.taboola.com *.bizrate.com *.connexity.net *.cnnx.link;connect-src 'self' *.akamaihd.net *.akstat.io *.bedbathandbeyond.com *.go-mpulse.net *.ostkcdn.com *.overstock.com *.swarmshop.com apple.com *.paypal.com *.kmsmep.com *.kmsmep.com *.comenity.net *.comenity.net *.breadpayments.com *.breadpayments.com *.bing.com *.bing.net *.braze.com *.clarity.ms api.consentjs.datagrail.io *.evergage.com *.facebook.net *.facebook.com *.google.com *.google.- strict-transport-security
max-age=31536000