tkmaxx.pl
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- cdn.jsdelivr.net×2
- www.googletagmanager.com×1
- www.juicer.io×1
Social
DNS records live
- NS
-
- a1-117.akam.net
- a14-66.akam.net
- a18-67.akam.net
- a22-64.akam.net
- a5-65.akam.net
- a7-66.akam.net
- MX
-
- 10 mxa-00081a02.gslb.pphosted.com
- 10 mxb-00081a02.gslb.pphosted.com
- 20 mx0a-00081a02.pphosted.com
- 20 mx0b-00081a02.pphosted.com
- Verified for
-
- Yahoo
Email authentication strong
- SPF
-
v=spf1 ip4:205.220.171.102 ip4:205.220.182.205 ip4:205.220.173.171 ip4:205.220.161.171 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; fo=1;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA OV R36
Expires in 65 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.gstatic.com *.juicer.io *.gigya.com *.flashtalking.com *.google.com *.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.google-analytics.com *.gigya.com *.cookielaw.org *.juicer.io *.maxmind.com *.youtube.com *.onetrust.com *.ytimg.com *.facebook.net *.ckeditor.com *.cookielaw.org qa1-loyalty.stage.hogarth.homesense.ie *.google.com *.gstatic.com *.googletagmanager.com unpkg.com cdn.jsdelivr.net cdnjs.cloudflare.com *.js-agent.newrelic.com *.juicer.io *.newrelic.com; object-src 'self'; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.google-analytics.com *.gigya.com *.cookielaw.org *.juicer.io *.onetrust.com *.ckeditor.com *.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com; img-src 'self' 'unsafe-eval' data: *.adnxs.com *.mookie1.com *.fbcdn.net *.imgur.com *.google-analytics.com *.doubleclick.net *.ipredictive.com *.gstatic.com *.googleapis.com *.gigya.com *.facebook.com *.ckeditor.com *.cookielaw.org *.js-agent.n
Links to (13)
- facebook.com×1
- homesense.com×1
- homesense.ie×1
- instagram.com×1
- tiktok.com×1
- tjx.com×1
- tkmaxx.at×1
- tkmaxx.com×1
- tkmaxx.de×1
- tkmaxx.es×1
- tkmaxx.ie×1
- tkmaxx.nl×1
- youtube.com×1
Linked from (5)
- jobfinder.pl×1
- tkmaxx.ie×1
- homesense.ie×1
- tkmaxx.nl×1
- tkmaxx.com×1