shoestation.com

.com crawl

First seen 2026-04-20 · Last seen 2026-05-14 · ok HTTP/1.1 200 6466 ms crawled 2026-05-14

US · 172.66.172.159 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Online Shoe Store, Boots, Sandals, Sneakers | Shoe Station
Description
Shoe Perks members get free shipping & exclusive rewards! Shop Shoe Station for amazing deals on shoes, boots, sandals, & sneakers for the whole family.
Language
en-US
Canonical
https://www.shoestation.com
Translations
  • en ×2

Technology

CDN
Cloudflare
CMS
Gatsby
Analytics
  • Google Tag Manager
Cookie consent
  • OneTrust
Fonts
  • Adobe Fonts
Third-party hosts loaded (7)
  • cdn.media.amplience.net×16
  • scvl.a.bigcontent.io×11
  • use.typekit.net×3
  • cdn.cookielaw.org×1
  • try.abtasty.com×1
  • www.google.com×1
  • www.googletagmanager.com×1

Registration

Registrar
Register.com - Network Solutions, LLC
Created
2001-12-12
Expires
2035-12-12 3492 days left
Updated
2025-12-13
Name servers
  • ben.ns.cloudflare.com
  • dana.ns.cloudflare.com

DNS records live

NS
  • ben.ns.cloudflare.com
  • dana.ns.cloudflare.com
MX
  • 0 scvl-com.mail.protection.outlook.com
Verified for
  • DocuSign
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 ip4:12.130.199.16/28 ip4:32.132.138.58 ip4:32.142.76.190 include:spf.protection.outlook.com include:docebosaas.com ~all
softfail (~all)
DMARC
v=DMARC1;p=quarantine;rua=mailto:trmoderation@scvl.com
policy: quarantine
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArkIZXw7u/gzJPR8Iax/mUqJzn2jTfmIo5yhvaOH7qqbASakIaWwecwFSbOTlKLPU6NCzGqH3fhn31a…
selectors probed

Certificate (current)

WE1
from 2026-05-07 to 2026-08-05
Expires in 77 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.shoestation.com/

present
  • strict-transport-security
  • content-security-policy
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-resource-policy
findings
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src *.ipredictive.com *.amazon-adsystem.com *.cdn.content.amplience.net cdn.media.amplience.net cdn.static.amplience.net *.staging.bigcontent.io *.attn.tv 'self' 'unsafe-eval' https://service.force.com/ https://capig.shoestation.com *.bazaarvoice.com uk.cdn-net.com six.cdn-net.com mpsnare.iesnare.com https://secure.cataboom.com/ *.my.site.com shoecarnivalsf360.my.salesforce.com *.facebook.com *.facebook.net ad.doubleclick.net td.doubleclick.net 9132531.fls.doubleclick.net *.googleapis.com *.googletagmanager.com *.doubleclick.net *.google.com *.youtube.com https://na-assets.playground.klarnaservices.com js.klarna.com js.playground.klarna.com x.klarnacdn.net *.klarnaservices.com *.klarna.com *.clarity.ms *.abtasty.com *.paypal.com *.paypalobjects.com https://account.venmo.com *.pbbl.co *.pinterest.com api.radar.io https://us.creativecdn.com/ *.sentry.io services.sheerid.com https://cdn.sitevibes.com tcapi.io *.wisepops.com https://wisepops.net *.zmags.com *.afterpay.com *.usablen
strict-transport-security
max-age=15552000; includeSubDomains
cross-origin-resource-policy
same-origin
content-security-policy-report-only
default-src 'self' *.klarna.com *.klarnaservices.com *.paypal.com *.paypalobjects.com *.afterpay.com *.cash.app *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.facebook.com *.facebook.net *.doubleclick.net *.amazon-adsystem.com *.bazaarvoice.com *.amplience.net cdn.cookielaw.org *.fullstory.com *.abtasty.com *.evergage.com *.sentry.io *.tiktok.com *.bing.com *.creativecdn.com *.mountain.com *.wisepops.com *.forter.com *.sitevibes.com *.thrive.today *.pbbl.co *.attn.tv *.ipredictive.com *.algolia.net *.algolianet.com *.onetrust.com *.pinterest.com *.adroll.com *.jsdelivr.net *.cloudfront.net *.typekit.net; script-src 'self' js.klarna.com x.klarnacdn.net *.paypal.com *.afterpay.com *.cash.app *.squarecdn.com *.google.com *.googletagmanager.com *.facebook.net 'unsafe-inline' cdn.cookielaw.org *.fullstory.com *.abtasty.com *.evergage.com *.googleapis.com storage.googleapis.com *.mountain.com loader.wisepops.com *.thrive.today *.pbbl.co *.attn.tv *.ipredictive.com *.jsd

Links to (3)

Linked from (1)