twofatcookies.com

.com crawl

First seen 2026-05-31 · Last seen 2026-05-31 · ok HTTP/1.1 200 2017 ms crawled 2026-06-01

US · 208.109.243.87 · AS398101 GoDaddy.com, LLC

Reputation 72/100 weak security headers multiple spf records no dmarc policy

Classifying

HTML metadata

Title
Two Fat Cookies -
Language
en
Generator
WordPress 6.6.5
Canonical
https://twofatcookies.com/
Feeds

Open Graph

url
https://twofatcookies.com/
title
Two Fat Cookies -
locale
en_US
description
BREAKFAST SERVED DAILY 8:00AM – 1:00PMLUNCH SERVED DAILY 10:30AM – 4:00PMTAKE-OUT ONLY (NO DINE-IN) BREAKFAST SERVED DAILY 8:00AM – 1:00PM, LUNCH SERVED DAILY 10:30AM – 4:00PMTAKE-OUT ONLY (NO DINE-IN) CHECK OUT OUR OTHER BRANDS  CHECK OUT OUR OTHER BRANDS

Technology

Server
Apache
CMS
WordPress 6.6.5
jQuery
3.7.1
Analytics
  • Google Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • www.google-analytics.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone

Registration

Registrar
Bluehost Inc.
Created
2007-11-08
Expires
2027-11-08 523 days left
Updated
2024-12-27
Name servers
  • ns1.bluehost.com
  • ns2.bluehost.com

DNS records live

NS
  • ns1.bluehost.com
  • ns2.bluehost.com
MX
  • 0 mail.twofatcookies.com
Verified for
  • Google

Email authentication weak

SPF
v=spf1 a mx ptr include:bluehost.com ?all
neutral (?all) · multiple SPF records
DMARC
not published
DKIM
  • default: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvWe6icOAk1wM+jZcdPiqsJjWm8QHN0RveRyIRie8/oKavHAPwpjp5Dr0BHn7YLtg3/NW7fgJm6VSlT…
selectors probed

Certificate (current)

R12
from 2026-04-17 to 2026-07-16
Expires in 44 days

HTTP security headers

Header hygiene 35/100 Checked live page: https://twofatcookies.com/

present
  • permissions-policy
findings
  • missing HSTS
  • missing Content Security Policy
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
Header values
permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")

Links to (6)

Linked from (1)