y.co

.co crawl

First seen 2026-04-21 · Last seen 2026-05-11 · ok HTTP/1.1 200 1243 ms crawled 2026-05-15

FI · 37.27.135.61 · AS24940 Hetzner Online GmbH

Reputation 75/100 listed in spam blocklist

Classifying

HTML metadata

Title
Y.CO | The Yacht Company | Full Service Luxury Yacht Company.
Description
Amazing Awaits. Y.CO is a full service superyacht company providing services in luxury yacht charter, sales, purchase, management, new build and project coordination.
Language
en
Generator
Astro v5.16.9
Canonical
https://y.co/

Open Graph

url
https://y.co/
title
Y.CO | The Yacht Company | Full Service Luxury Yacht Company
locale
en_
site name
Y.CO
description
Amazing Awaits. Y.CO is a full service superyacht company providing services in luxury yacht charter, sales, purchase, management, new build and project coordination.

Technology

CDN
Cloudflare
Server
BunnyCDN-FI1-1208
Analytics
  • Google Analytics
  • Google Tag Manager
Cookie consent
  • Usercentrics

Third-party hosts loaded (3)

  • www.googletagmanager.com×3
  • web.cmp.usercentrics.eu×2
  • www.google-analytics.com×1

Social

Contact

Phone

DNS records live

NS
  • gerardo.ns.cloudflare.com
  • rayne.ns.cloudflare.com
MX
  • 10 mx1-eu1.ppe-hosted.com
  • 10 mx2-eu1.ppe-hosted.com
TXT
Show 13 TXT records
  • KR+osAfGN8FC6Jc/wJhXAFEZR4aPJSZlOjtYI+lGxTYbqohnxiHlzKxFKWYNA81FJWH96e/0WLidyRL+7dUS+w==
  • MS=DF9C40422DC25BD421ECBFBF1CE1F737AF9A27BA
  • MS=ms88579881
  • Validity-Domain-Verification=aFyHATGsncgAWPW3N4f4CZyoLcU=
  • apple-domain-verification=k4mZIOl1NCZ5EcFT
  • google-gws-recovery-domain-verification=39282665
  • google-site-verification=-nUJCVNs_JdJIQBqhetu9zjN7LGMf0ZhD3PdfkgyXKM
  • google-site-verification=mm5vsI9tT_YoT-HuCVZXfanqXc_3e0bXmWTd8v1zVKo
  • hibp-verify=dweb_mnfiznpmpoasw2ruj2mh9i99
  • pardot1022683=26405c68a6c18ab2382db9a288b786b133b5f01d12c73e7e76d5973def17b534
  • ppe-3a0049077c4d80d3caaffafbbd8926cc5d868556
  • sending_domain1022683=970f8fdc35e4d55d1305a13bb24b24cadd7adb9d6dc6ca70ac64b91e9fc9b3a8
  • validity-domain-monitoring=WSevRnIp0goRipYT2WVQ5qTN6

Email authentication strong

SPF
v=spf1 redirect=y.co.hosted.spf-report.com
no all qualifier
DMARC
v=DMARC1;p=reject;pct=10;rua=mailto:acb34262@mxtoolbox.dmarc-report.com,mailto:dmarc@y.co,mailto:dmarc_agg@dmarc.everest.email;ruf=mailto:acb34262@forensics.dmarc-report.com,mailto:dmarc@y.co,mailto:dmarc_fr@dmarc.everest.email
policy: reject (enforced) · pct=10
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCjTIXZjy/pmhMD5a51tRNqWrfaNl+RImR849YnLTU6QwZ6gb9lUZLTA4U2oZq5sVvZZORBJtgqshk7Qyp+6m…
  • selector2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuLsihIHUCd+phGU4zGuA/Z+2SqosTm+6YA6woo3a8oV+/YN+OpqvtD65XGMZ7uY0VtxO1qwxjhr2QH…
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed

Certificate (current)

R13
from 2026-04-19 to 2026-07-18
Expires in 60 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://y.co/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
  • referrer-policy
  • permissions-policy
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
  • cross-origin-resource-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
Header values
referrer-policy
strict-origin-when-cross-origin
permissions-policy
geolocation=(), microphone=(), camera=(), fullscreen=(self)
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-assets.y.co https://www.googletagmanager.com https://*.clarity.ms https://*.pardot.com https://*.vimeocdn.com https://player.vimeo.com https://f.vimeocdn.com https://www.gstatic.com https://bat.bing.com http://go.y.co https://go.y.co https://snap.licdn.com/li.lms-analytics/insight.min.js https://*.google-analytics.com https://cht-srvc.net https://*.livechatinc.com https://*.cloudflareinsights.com https://*.usercentrics.eu https://*.zapier.com https://charter-ai-yco.zapier.app https://charter-ai-yco-public.zapier.app https://api.mapbox.com; style-src 'self' 'unsafe-inline' https://cdn-assets.y.co https://*.livechatinc.com https://api.mapbox.com; img-src 'self' data: https://cdn-assets.y.co https://*.mapbox.com https://video.y.co https://assets.y.co https://cdn-video.y.co https://cdn-image.y.co https://res.cloudinary.com https://www.google.co.uk/ads/ga-audiences https://bat.bing.net https://bat.bing.com https
strict-transport-security
max-age=31536000
cross-origin-opener-policy
same-origin-allow-popups
cross-origin-embedder-policy
unsafe-none
cross-origin-resource-policy
cross-origin

Links to (5)

Linked from (1)