tempursealy.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Gatsby
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- tempursealy2-assets.cloudfront.tsi-prod.tsiaws.com×56
- www.googletagmanager.com×1
Registration
- Registrar
- MarkMonitor Inc.
- Created
- 2013-03-04
- Expires
- 2027-03-04 289 days left
- Updated
- 2026-01-31
- Name servers
-
- ha1.markmonitor.zone
- ha2.markmonitor.zone
- ha3.markmonitor.zone
- ha4.markmonitor.zone
DNS records live
- NS
-
- ha1.markmonitor.zone
- ha2.markmonitor.zone
- ha3.markmonitor.zone
- ha4.markmonitor.zone
- MX
-
- 0 mxa-0029ae01.gslb.pphosted.com
- 0 mxb-0029ae01.gslb.pphosted.com
- TXT
-
Show 16 TXT records
google-site-verification=GFuVswl7-DhwlPdMXC5M5tap2D4ncFcXtaZF3KA8Ipsintersight=f7e7abb0bbc8f3231997a58fafa2dddc6b1a173170d0da7dc0a95052e295ac4e8AgeUQAVbcIqnQgVWdHsZdPNgDSBIZ0dRoAwBvY7coe6f6Hi/GV3Vdl4u9kHjcMrqR8oUjP+mJ4Bp+9iKoTEKA==figma-domain-verification=415ce1c13a6ca7034389357374b575f3670e6f7881ce6771a8fc7df3c55eea37-1729597901MS=ms506324031adf592024e1e2c73xMUeKgTIMPHGRM9Fvs81sah21raa4imq1cqqefc4bbrptbipu1dosl3n0mvt73hlkvgba9p_ek0z2rmff359pz3dq3sk7trujqozynu3785d0a004f04330093d2ee81db21c4d8f12f08089bd2298a0f7889d473dc68ff8af474f347671fbbf5880418afaee2c7834teamviewer-sso-verification=fe300da01ace4159b1136dc40f698237onetrust-domain-verification=168342e80fa242d3905264e8043124fdidentrust_validate=MEl/mPeVnIoFgU/Ks5cLxN3c7APDh0c/tmbRx/koTv36identrust_validate=itOKOr4AEjn6/ZR9NO0GaHoZP4xwcKpwM2t4NxJhXmU2
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:mail.zendesk.com include:_spf.salesforce.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: reject (enforced) - DKIM
-
- k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApt7qz6bSTeQDxBzVulGaPjhMmYz/ddkJhhl/TAbqrJp8phG01uFmXcU1u32HoKwnDs4TyKtNgl9HgdmOej…
selectors probed - k1:
Certificate (current)
E7
Expires in 31 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(self), battery=(), camera=(), display-capture=(), document-domain=(*), encrypted-media=(), fullscreen=(self), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), oversized-images=(self), payment=(self), picture-in-picture=(), publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=(), usb=(), vibrate=(), vr=(), web-share=()- x-content-type-options
nosniff- content-security-policy
img-src 'self' blob: data: https://*.algolia.net https://*.litix.io https://*.wistia.com https://*.wistia.net https://analytics.google.com https://cdn.cookielaw.org/ https://fast.wistia.com https://fast.wistia.net https://geolocation.onetrust.com/ https://o19836.ingest.us.sentry.io/ https://privacyportal-de.onetrust.com/ https://privacyportalde-cdn.onetrust.com/ https://tempursealy2-assets.cloudfront.tsi-prod.tsiaws.com/ https://www.google-analytics.com https://www.googletagmanager.com/; font-src 'self' blob: data: https://*.algolia.net https://*.litix.io https://*.wistia.com https://*.wistia.net https://analytics.google.com https://cdn.cookielaw.org/ https://fast.wistia.com https://fast.wistia.net https://geolocation.onetrust.com/ https://o19836.ingest.us.sentry.io/ https://privacyportal-de.onetrust.com/ https://privacyportalde-cdn.onetrust.com/ https://tempursealy2-assets.cloudfront.tsi-prod.tsiaws.com/ https://www.google-analytics.com https://www.googletagmanager.com/; base-uri; con- strict-transport-security
max-age=63072000- cross-origin-opener-policy
same-origin