tutcosureheat.com

.com crawl

First seen 2026-05-10 · Last seen 2026-05-16 · ok HTTP/1.1 200 10040 ms crawled 2026-05-16

US · 3.222.45.208 · AS14618 Amazon.com, Inc.

Reputation 94/100 dmarc monitor-only

sector manufacturing type homepage

HTML metadata

Title
Electrified Process Heating Solutions
Description
TUTCO SureHeat Serpentine™ Technology. allows us to produce air heatiers that are compact, versatile, quick, and accurate.
Language
en
Canonical
https://www.tutcosureheat.com
Translations
  • en

Open Graph

url
https://www.tutcosureheat.com
title
Electrified Process Heating Solutions
locale
en_US
site name
SureHeat
description
TUTCO SureHeat Serpentine™ Technology. allows us to produce air heatiers that are compact, versatile, quick, and accurate.

Technology

Server
nginx
CMS
Gatsby
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • d3dmuhgh3oppig.cloudfront.net×46
  • www.googletagmanager.com×2
  • www.google.com×1

Social

Contact

Email
Phone
Address
22 Industrial Drive, 03833, Exeter, NH, US

Registration

Registrar
CSC Corporate Domains, Inc.
Created
2017-09-14
Expires
2026-09-14 116 days left
Updated
2025-09-10
Name servers
  • a1-211.akam.net
  • a16-66.akam.net
  • a28-64.akam.net
  • a7-64.akam.net

DNS records live

NS
  • a1-211.akam.net
  • a16-66.akam.net
  • a26-66.akam.net
  • a28-64.akam.net
  • a7-64.akam.net
  • a9-66.akam.net
MX
  • 0 tutcosureheat-com.mail.protection.outlook.com
TXT
  • mandrill_verify.xzRnhkFmBF0afkCWlYyXEw
Verified for
  • Microsoft 365

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com -all
strict (-all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

R12
from 2026-05-05 to 2026-08-03
Expires in 74 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.tutcosureheat.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' *.youtube.com unpkg.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net *.gstatic.com *.clarity.ms d3dmuhgh3oppig.cloudfront.net maps.gstatic.com *.googleapis.com *.google-analytics.com cdnjs.cloudflare.com assets.zendesk.com connect.facebook.net *.googletagmanager.com *.google.com www.webtraxs.com s3.amazonaws.com *.doubleclick.net analytics.ahrefs.com cdn.amplitude.com browser.sentry-cdn.com; frame-src 'self' *.gstatic.com *.clarity.ms *.youtube.com cdn.jsdelivr.net d3dmuhgh3oppig.cloudfront.net assets.zendesk.com *.facebook.com s-static.ak.facebook.com tautt.zendesk.com *.googletagmanager.com *.google.com td.doubleclick.net; worker-src 'self' blob:; object-src 'self';
strict-transport-security
max-age=31536000; includeSubDomains; preload
cross-origin-opener-policy
same-origin

Links to (9)

Linked from (2)