stauff.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Usercentrics
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (17)
- stauff.com.br×4
- app.usercentrics.eu×3
- stauff.com.cn×3
- stauff.fr×3
- stauff.it×3
- stauff.ru×3
- www.stauffusa.com×3
- player.vimeo.com×2
- api.usercentrics.eu×1
- chat1090.realperson.cloud×1
- stauff.co.nz×1
- stauff.co.uk×1
- stauff.com.au×1
- stauff.in×1
- stauffcanada.com×1
- talk.hyvor.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1996-05-31
- Expires
- 2030-05-30 1471 days left
- Updated
- 2022-10-17
- Name servers
-
- ns1-03.azure-dns.com
- ns2-03.azure-dns.net
- ns3-03.azure-dns.org
- ns4-03.azure-dns.info
DNS records live
- NS
-
- ns1-03.azure-dns.com
- ns2-03.azure-dns.net
- ns3-03.azure-dns.org
- ns4-03.azure-dns.info
- MX
-
- 10 stauff-com.mail.protection.outlook.com
- TXT
-
Show 7 TXT records
MS=ms16969615A4maTyyU9BKivc46rQ0yZxj61m7rA82sXxd6OMSJRYp1IInibQcJwYfUuAAxWa2XKS4ww13t9roYgbGcOEWWeA==apple-domain-verification=KOn6CxSDuqyrYW5imiro-verification=29125452fbbfbb054d98ca2d561a3c68bb4076c3iid-domain-verification=440a8ba5-1e47-4f9f-b051-70efeb0e0921canva-site-verification=NRPMCXbh8h672YHZV4X--Qgoogle-site-verification=BhSDnDDm_sVwPTkdLdx6Nl9BOj2qPgwdhDMsf_J7ypI
Email authentication strong
- SPF
-
v=spf1 include:spf.dynect.net include:spf.cloud.ci-solution.com ip4:62.153.200.198 ip4:85.10.214.4 ip4:92.39.18.14 include:spf.protection.outlook.com include:spf.strold.io ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDI5notVxTFIkFqCrH2v+NKKlgNJNtBTK2QecK114BD1usZyE9i91IPvZCkTQeQTVnoKGR9ofCS0S7KAFwGDi… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwEjz8rxjVxsIRsJHxcKucr3buc8JkWLeBiJXaGcLxBZ86oZPw0jtRASG9QSwcc5yccXW7wes0aJniA…
selectors probed - selector1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 269 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing HSTS
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self' https://*.stauff.bloomreach.cloud cms.stauff.com; sandbox allow-downloads allow-forms allow-modals allow-pointer-lock allow-popups allow-popups-to-escape-sandbox allow-same-origin allow-scripts allow-top-navigation; base-uri 'self'; form-action 'self' https://stauff.com adyen.com https://login.microsoftonline.com/ *.paypal.com html-assets.stauff.com live.adyen.com checkoutshopper-live.adyen.com