sellerise.com
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- api.mapbox.com×2
- dev.visualwebsiteoptimizer.com×1
- r.wdfl.co×1
- widget.trustpilot.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- NameCheap, Inc.
- Created
- 2017-12-11
- Expires
- 2028-12-11 936 days left
- Updated
- 2025-11-18
- Name servers
-
- chloe.ns.cloudflare.com
- kareem.ns.cloudflare.com
DNS records live
- NS
-
- chloe.ns.cloudflare.com
- kareem.ns.cloudflare.com
- MX
-
- 1 smtp.google.com
- TXT
-
Show 4 TXT records
ahrefs-site-verification_1359efe9f4d4f71186f8919c3705b656813f369370c81fcbb591c61971571df5atlassian-domain-verification=RTUu9uha/iz6dU5RBzvcBxaaa6XNnvhdWa9RgvAKzMDns8Eu6T/b0LDi1s6eBpQngoogle-site-verification=I8lKzb6MFO1MosknHmTLy7kgSUQLiWOBtnzbPbMe_OAstripe-verification=5abae8ac1dbe0e35ffa4cb348416f1b094854825d12b1fec0e390a8c610043ae
Email authentication partial
- SPF
-
v=spf1 mx ip4:45.76.16.188 ip6:2001:19f0:5c01:1335:5400:02ff:fec2:f14f include:spf.mandrillapp.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
WE1
Expires in 68 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin, no-referrer-when-downgrade- x-frame-options
SAMEORIGIN, DENY, SAMEORIGIN- permissions-policy
geolocation=(), camera=(), microphone=(), fullscreen=(self "https://www.youtube.com" "https://scribe.com" "https://widget.trustpilot.com")- x-content-type-options
nosniff- content-security-policy
default-src 'self' https: data: blob:;script-src 'self' https: blob: https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://widget.intercom.io https://js.intercomcdn.com https://app.intercom.io 'unsafe-eval' 'nonce-hIRaqvr8iL9gC8eq799hCA==';style-src 'self' https: 'unsafe-inline';style-src-elem 'self' https: 'unsafe-inline';style-src-attr 'unsafe-inline';img-src * data: blob:;font-src 'self' https: data:;connect-src 'self' https: ws: wss: https://api-iam.intercom.io https://api-iam.eu.intercom.io https://nexus-http.intercom.io https://nexus-http.eu.intercom.io wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io wss://nexus-websocket-a.eu.intercom.io wss://nexus-websocket-b.eu.intercom.io https://intercom-sheets.com;media-src 'self' https: data: blob:;frame-src 'self' https://app.intercom.com https://app.eu.intercom.com https://js.intercomcdn.com https://*.trustpilot.com https://www.youtube.com https://www.youtube-nocookie.com https://scribe- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin