parcel2go.com
HTML metadata
Technology
- CDN
- Cloudflare
Third-party hosts loaded (2)
- images.ctfassets.net×53
- assets.ctfassets.net×1
Social
Contact
- Phone
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 1999-10-20
- Expires
- 2027-10-20 519 days left
- Updated
- 2025-06-13
- Name servers
-
- lee.ns.cloudflare.com
- tricia.ns.cloudflare.com
DNS records live
- NS
-
- lee.ns.cloudflare.com
- tricia.ns.cloudflare.com
- MX
-
- 0 parcel2go-com.mail.protection.outlook.com
- TXT
-
Show 14 TXT records
google-site-verification=Vi7HptYRLW2IoEUKiQb1eB_qjQkjBDJf8vAh7FCLCEkyahoo-verification-key=aSuqybzk7SZaNDOuCx9L5XdTmbgSRmJ4Ls9LIvrClVw=atlassian-domain-verification=aGrG5sDPL25PDx4HuwUbxbIejgtOfCO/jFoeuC9lWuRmDjvSMpPdSalSYKAFcJMUklaviyo-site-verification=WGiTBxMS=ms18047107google-site-verification=KdJHv3nCb4cKXDnV6ohTAQ-OIZdwdFS5YaEQtc_Zveggoogle-site-verification=Qym6oR6ysieCvV6v0kQgAsDPyHqpDq3V_CWuak_yqZopostman-domain-verification=5376e1a0fb6611d64f7f01f4773053cdd8f4b26a29675a71267bf6483a72c44088cad77b40d165968cc67e67e13d02a62414098293a39c56b7d0f409ff533f99loaderio=c8b92d3cc2ee174b32cc4761805d380bspycloud-domain-verification=a5e1e0a6-d413-4b39-a3d7-1163b9c457degoogle-site-verification=Hk5BB3227psoYC2ilKAQWuXybzFEpnK7e4eXYYCjyWQapple-domain-verification=v1iwrCHTTrflhVVrspycloud-domain-verification=a472ab91-0603-45ef-9b4e-c68c9c5d9167google-site-verification=Jwh0QxpecgbfkPiUgQ0whcEGEy5W0feM0EVoGnCLMMA
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:spf.netnorth.co.uk include:aspmx.sailthru.com include:amazonses.com include:spf.mail.parcel2go.biz ip4:82.148.255.82 include:spf.smtp2go.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:c53cb4ee0ae94f018c816373b21e937a@dmarc-reports.cloudflare.netpolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQYu3xcKVQ45BulUbNe87OFLtyS/ZPHu2Y8u9JZZmnrX8paGt00pWeJSut+YIbhFJ2UlVnsWqTKdM5hCaXRf…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 28 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(self), battery=(), camera=(self), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(self), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(self), gamepad=(), speaker-selection=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tyviso.com t.contentsquare.net *.redditstatic.com *.quora.com app.contentsquare.com widget.trustpilot.com *.googleoptimize.com *.googletagmanager.com *.google-analytics.com *.ttwstatic.com *.tiktok.com *.instagram.com *.googleapis.com *.google.com *.gstatic.com *.ggpht.com *.googleusercontent.com *.googleadservices.com https://*.googlesyndication.com googleads.g.doubleclick.net analytics.google.com tagmanager.google.com *.dwin1.com bat.bing.com smct.co *.smct.co *.smct.io smct.io connect.facebook.net *.clarity.ms *.sail-horizon.com api.sail-personalize.com *.algolianet.com *.nickelled.com *.contentsquare.net challenges.cloudflare.com *.boldchat.com static.cloudflareinsights.com snap.licdn.com *.lambda-url.eu-west2.on.aws *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com https://unpkg.com *.talkdeskapp.com *.talkdeskapp.eu app.termly.io lantern.roeyecdn.com *.creativecdn.com *.adscdn.com analytics.tikt- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin