yokltours.com

.com crawl

First seen 2026-05-12 · Last seen 2026-05-12 · ok HTTP/1.1 200 508 ms crawled 2026-05-18

US · 172.67.217.199 · AS13335 Cloudflare, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Yokl Tours | Discover Delicious Food Tours in Pennsylvania
Description
Join Yokl Tours and enjoy the historical food tours in Hershey and Linglestown, PA. Book online and bring your family and friends to get that fun-filled stomach!
Language
en-US
Canonical
https://yokltours.com/

Open Graph

url
https://yokltours.com/
title
Yokl Tours | Discover Delicious Food Tours in Pennsylvania
site name
Yokl
description
Join Yokl Tours and enjoy the historical food tours in Hershey and Linglestown, PA. Book online and bring your family and friends to get that fun-filled stomach!

Technology

CDN
Cloudflare
CMS
WordPress

Third-party hosts loaded (3)

  • cdnjs.cloudflare.com×2
  • fareharbor.com×1
  • stats.wp.com×1

Contact

Phone

Registration

Registrar
GoDaddy.com, LLC
Created
2024-10-14
Expires
2026-10-14 146 days left
Updated
2025-10-15
Name servers
  • lady.ns.cloudflare.com
  • rudy.ns.cloudflare.com

DNS records live

NS
  • lady.ns.cloudflare.com
  • rudy.ns.cloudflare.com
MX
  • 0 smtp.google.com
Verified for
  • Google

Email authentication weak

SPF
not published
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-03-23 to 2026-06-22
Expires in 32 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://yokltours.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https: http: blob:; font-src 'self' data: https:; connect-src 'self' https: wss:; media-src 'self' https:; object-src 'none'; base-uri 'self'; frame-src 'self' https:; frame-ancestors 'self'
strict-transport-security
max-age=31536000
cross-origin-opener-policy
same-origin-allow-popups

Links to (3)

Linked from (1)