tauck.co.uk

.uk crawl

First seen 2026-05-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 33193 ms crawled 2026-05-18

US · 45.60.122.98 · AS19551 Incapsula Inc · dead nameservers

Reputation 62/100 dead nameservers no dmarc policy

sector travel type homepage

HTML metadata

Title
Escorted Tours, Small Ship and River Cruises and Family Travel | Tauck
Description
Tauck's enriching guided tours, small ship cruises, river cruises and family travel take you to all seven continents.
Language
en
Canonical
https://www.tauck.co.uk/
Translations
  • en

Technology

Server
Microsoft-IIS
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • www.tauck.com×8
  • api.tiles.mapbox.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone

DNS records dead

NS
  • ns3.worldnic.com
  • ns4.worldnic.com
MX
  • 10 mx.usa.net
  • 20 mx.ct.mbox.net
TXT
  • _ad86yutmclttxymiutoq8mezve6w8nb
  • gxgsbldpc01tpp0ftz2sfck9tp68vfbr
Verified for
  • GlobalSign
  • Microsoft 365

Email authentication weak

SPF
v=spf1 mx ip4:12.111.58.66 ip4:46.25.70.0/24 ip4:195.188.244.0/24 ip4:194.72.251.0/24 ip4:20.68.185.242 include:spf.usa.net include:sent-via.netsuite.com include:spf.protection.outlook.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificates

Loading certificate

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.tauck.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
content-security-policy
default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline';font-src * data: blob: 'unsafe-inline';frame-ancestors * data: blob: ;
strict-transport-security
max-age=31536000; includeSubDomains

Links to (4)