woostersbakery.com

.com crawl

First seen 2026-04-21 · Last seen 2026-05-11 · ok HTTP/1.1 200 1508 ms crawled 2026-05-14

GB · 77.72.2.128 · AS12488 Krystal Hosting Ltd

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Wooster’s Bakery
Description
Suffolk bakery specialising in traditional and artisan bread, pastries and cakes. Find us at our shops at Wyken Vineyards and Bury St Edmunds.
Language
en-GB
Generator
WordPress 6.9.4
Canonical
https://woostersbakery.com/

Open Graph

url
https://woostersbakery.com/
title
Wooster’s Bakery
locale
en_GB
site name
Wooster’s Bakery
description
Suffolk bakery specialising in traditional and artisan bread, pastries and cakes. Find us at our shops at Wyken Vineyards and Bury St Edmunds.

Technology

Server
LiteSpeed
CMS
WordPress

Third-party hosts loaded (1)

  • gmpg.org×1

Social

Contact

Phone

Registration

Registrar
Bluehost Inc.
Created
2022-01-01
Expires
2027-01-01 226 days left
Updated
2025-12-17
Name servers
  • ns1.krystal.uk
  • ns2.krystal.uk

DNS records live

NS
  • ns1.krystal.uk
  • ns2.krystal.uk
MX
  • 10 mx1.krystal.io
  • 20 mx2.krystal.io
TXT
  • google-site-verification=y3hojOjDsgkPPH1pb0PbVIPpX08jLlue1WMJwnRTf4I

Email authentication partial

SPF
v=spf1 ip4:77.72.2.128 +a +mx include:relay.k.io ~all
softfail (~all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • default: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAueQjWhOtyExEq3YF/Qnal/ZAHL5/wcLf1VbgUbqOKbpl+CdSTrPUP/W1GE3KIkAuW3D+S+f82iy2wu…
selectors probed

Certificate (current)

R13
from 2026-04-29 to 2026-07-28
Expires in 69 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://woostersbakery.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=(), xr-spatial-tracking=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval' data:; style-src * 'unsafe-inline'; img-src * data:; font-src * data:; frame-src *; connect-src *; media-src * blob:; worker-src 'self' blob:; base-uri 'self'; form-action *; frame-ancestors 'self';
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (2)

Linked from (1)