tinmustard.com

.com crawl

First seen 2026-06-03 · Last seen 2026-06-03 · ok HTTP/1.1 200 353 ms crawled 2026-06-03

CA · 23.227.38.65 · AS13335 Cloudflare, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Tin Mustard - Delicious Wholegrain Mustards Made in Brooklyn, NY
Description
Tin Mustard is an artisanal mustard brand producing delicious wholegrain mustards and dry mustard blends in the Red Hook neighborhood of Brooklyn, NY.
Canonical
https://tinmustard.com/

Open Graph

url
https://tinmustard.com/
title
Tin Mustard - Delicious Wholegrain Mustards Made in Brooklyn, NY
site name
Tin Mustard
description
Tin Mustard is an artisanal mustard brand producing delicious wholegrain mustards and dry mustard blends in the Red Hook neighborhood of Brooklyn, NY.

Technology

CDN
Cloudflare
CMS
Joomla
jQuery
2.2.3 known XSS (<3.5)
Fonts
  • Google Fonts
Third-party hosts loaded (7)
  • fonts.googleapis.com×3
  • cdn.shopify.com×2
  • shop.app×2
  • ajax.googleapis.com×1
  • cdn-relatable.heliumdev.com×1
  • monorail-edge.shopifysvc.com×1
  • staticxx.s3.amazonaws.com×1

Social

Registration

Registrar
GoDaddy.com, LLC
Created
2006-10-29
Expires
2026-10-29 145 days left
Updated
2025-10-30
Name servers
  • ns49.domaincontrol.com
  • ns50.domaincontrol.com

DNS records live

NS
  • ns49.domaincontrol.com
  • ns50.domaincontrol.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
Verified for
  • Google

Email authentication weak

SPF
v=spf1 include:dc-aa8e722993._spfm.tinmustard.com ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

YE1
from 2026-05-29 to 2026-08-27
Expires in 83 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://tinmustard.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • short HSTS max-age
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
strict-transport-security
max-age=7889238

Links to (4)

Linked from (1)