thelevelgroup.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Gatsby
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (1)
- static.cloudflareinsights.com×1
Contact
- Phone
Registration
- Registrar
- Wild West Domains, LLC
- Created
- 2010-11-15
- Expires
- 2027-11-15 532 days left
- Updated
- 2025-11-16
- Name servers
-
- ns57.domaincontrol.com
- ns58.domaincontrol.com
DNS records live
- NS
-
- ns57.domaincontrol.com
- ns58.domaincontrol.com
- MX
-
- 0 thelevelgroup-com.mail.protection.outlook.com
- TXT
-
sfcc_verification_bbtb=b11186e6f0bbbfe7d9d38ee7e2b53e6dd948a8ef7d9dded47583e81b5c0124617e0-6r9-2t1
- Verified for
-
- Apple
- Cursor
- Microsoft 365
- OpenAI
Email authentication strong
- SPF
-
v=spf1 ip4:37.202.19.130 include:spf.protection.outlook.com include:spf.kibocommerce.com include:mail.zendesk.com include:partnerescalations.zendesk.com a:production.store.thelevelgroup.demandware.net include:turbo-smtp.com ip4:54.244.52.142 ip4:54.201.207.102 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantinepolicy: quarantine - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCizcvrgLVZU+kiuY2taHhKGkh3fe7dpuOsoeFKJLVQtIoHEknHS1PPOtK+rGTR+f1cgSvdPQcaMSWzHbgKDS… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCpFV7w/pVaRDjn99TxZX5+p9Vl9/DnBQZWx8pxZT3dZaj9bKg7nJUQjLfdE7geGTsFNuWVlnWHYGqA/n7rgX… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA31WrwqZzYVsKfJ5OJB6FhhqTgEhohN5f9bp86x97szuW0VoUO/DwG9YtUiMK40RLVis/P45zxelLTDLnjv… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx5nhrrHnRg529Sho/fz3KqXt3S7AIvJ3IQubUXZKd69jNg5+OXws/R4lt7wjsMk+h05SckttdW++V198Or…
selectors probed - selector1:
Certificate (current)
R13
Expires in 65 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
img-src 'self' *.commercecloud.salesforce.com fonts.gstatic.com www.googletagmanager.com cdn.builder.io data:;script-src 'self' 'unsafe-eval' storage.googleapis.com www.google.com;connect-src 'self' api.cquotient.com ssr-gtm.thelevelgroup.com cdn.cookielaw.org www.google-analytics.com geolocation.onetrust.com privacyportal-de.onetrust.com cdn.builder.io;script-src-elem 'self' www.google.com www.gstatic.com www.googletagmanager.com cdn.cookielaw.org www.google-analytics.com cdn.builder.io edge.fullstory.com 'unsafe-inline';default-src 'self' www.google.com;upgrade-insecure-requests;frame-ancestors *.builder.io builder.io localhost:3000 /tlg-corporate-develop.mobify-storefront.com;base-uri 'self';block-all-mixed-content;font-src 'self' https: data:;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'- strict-transport-security
max-age=600; includeSubDomains