tkmaxx.es
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn.cookielaw.org×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- a1-117.akam.net
- a14-66.akam.net
- a18-67.akam.net
- a22-64.akam.net
- a5-65.akam.net
- a7-66.akam.net
- MX
-
- 10 mxa-00081a02.gslb.pphosted.com
- 10 mxb-00081a02.gslb.pphosted.com
- 20 mx0a-00081a02.pphosted.com
- 20 mx0b-00081a02.pphosted.com
- TXT
-
_ou5vec9vnok7b4uch5knp44wng9wmy0_njvh3e1yxpmv0lkj9bp7xjeos1jkd1n_8k1n29j40stup3529pgumupmij0hvc4
Email authentication strong
- SPF
-
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; fo=1;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G3 TLS ECC SHA384 2020 CA1
Expires in 187 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' https://*.redditstatic.com https://*.googletagmanager.com connect.facebook.net www.google.com www.gstatic.com *.google-analytics.com maps.googleapis.com cdn.cookielaw.org; frame-src 'self' www.google.com www.googletagmanager.com www.youtube.com *.doubleclick.net; frame-ancestors 'self'
Linked from (4)
- tkmaxx.ie×1
- homesense.ie×1
- tkmaxx.nl×1
- tkmaxx.pl×1