winwardsilks.com
HTML metadata
Technology
- CDN
- Cloudflare
- Fonts
-
- Font Awesome
- Google Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (8)
- images.junipercdn.com×20
- use.fontawesome.com×4
- cdn.firebase.com×1
- cdnjs.cloudflare.com×1
- fast.fonts.net×1
- fonts.googleapis.com×1
- www.google.com×1
- www.youtube.com×1
Social
Contact
- Phone
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 1996-04-18
- Expires
- 2027-04-19 334 days left
- Updated
- 2026-04-19
- Name servers
-
- lady.ns.cloudflare.com
- louis.ns.cloudflare.com
DNS records live
- NS
-
- lady.ns.cloudflare.com
- louis.ns.cloudflare.com
- MX
-
- 0 winwardsilks-com.mail.protection.outlook.com
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject;policy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCp6mgIP6p6uwOSko8lFsPc08DgC5OR2BxAbkC6mbs0aByvUQGF6n07I5+3NApC/0E0inL2f3HWTbXcZG5FEI… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 67 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' https://winwardsilks.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://popupmaker.com https://*.googletagmanager.com https://*.bronto.com wss://*.hotjar.com https://snapwidget.com https://*.nr-data.net https://*.newrelic.com https://*.calendly.com https://*.flodesk.com https://*.getsitecontrol.com https://*.sharethis.com https://*.vistag.com https://*.privy.com https://*.zopim.com https://*.zdassets.com *.mailchimp.com *.hotjar.com http://localhost:* https://*.powr.io https://*.tawk.to https://*.pinterest.com https://cdn.lightwidget.com js.hs-scripts.com https://unpkg.com https://www.google.com *.google.com *.google-analytics.com http://js.hs-analytics.net https://cdn.firebase.com https://cdnjs.cloudflare.com https://d2zah9y47r7bi2.cloudfront.net https://*.firebaseio.com https://*.vo.msecnd.net https://browser-update.org https://api.instagram.com *.fonts.net/ http://browser-update.org http://cdn.datatables.net http://cdn.heapanalytics.com *.googleapis.com/- strict-transport-security
max-age=31536000; includeSubdomains