abri.co.uk
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- JS framework
- Next.js
Third-party hosts loaded (2)
- d2t1vdoabw4hm5.cloudfront.net×3
- cc.cdn.civiccomputing.com×1
Social
Contact
- Phone
Registration
- Registrar
- 123-Reg Limited t/a 123-reg
- Created
- 2016-12-03
- Expires
- 2026-12-03 196 days left
- Updated
- 2024-08-19
- Name servers
-
- ns63.domaincontrol.com.
- ns64.domaincontrol.com.
DNS records live
- NS
-
- ns63.domaincontrol.com
- ns64.domaincontrol.com
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 10 TXT records
0B2WFDL78RNBWWHEJ4UEPSAHMZ1VM5KVSV9NS7LIpp9g5b7b6c2vubo1u7mk6nb0esusp63qb9c7siura46svlt60qpeautodesk-domain-verification=hxftEv-2f4pbAUV5t9Kxhave-i-been-pwned-verification=289b475e9ad4b8ec0c8faa148701ac42atlassian-sending-domain-verification=c6b249ed-2008-40f8-940e-b93679db5477d9uj2mu23d26pathep7pkbgt3ptrend-micro-v1-domain-verification.4526ea02d2a5f7a3f35d8bc6367a6e22=6a5f5c28-fd9d-4639-bd55-2a98c1ba9f14K9AUHQUY1K36X6QK5533S3YDTZHS64VNXKGJ7CKTFoxit-domain-verification=16dbacfbc430751366ba7bf3d17040cb
- Verified for
-
- Apple
- Atlassian
- DocuSign
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:192.254.125.237 ip4:153.92.242.237 ip4:168.245.93.86 a:em3997.cascadecloud.co.uk a:cascadecloud.co.uk include:_spf.alchemer.eu include:eu._netblocks.mimecast.com include:sendgrid.net include:spf.protection.outlook.com include:_vccnets.8x8.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:2012ffd7b007710@rep.dmarcanalyzer.com; ruf=mailto:2012ffd7b007710@for.dmarcanalyzer.com; fo=1;policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1e2QdVU3FTrf91+Um7cwopod854ihPsoEC/iD//6JAyjVPeKaSiuUkUiKldppOkTZkXfFCblvZuIrt… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv+Yo1mk8H0xQTO3XSiRz6hsM2R1/ylbNkGPlGAOf05kBd7fv4edR+mR3amG0eXVAcbCmXLqnqFHVqoHRlZ… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDVaaXQQM2PfUg9Yi31+N/RCJVZ+hr/zI/U1VwdD/dhMgpmqcM2TuJevAW39N11kjF0ZCx0zGhwQ+S/fkzLpdfKh8…
selectors probed - selector1:
Certificate (current)
R12
Expires in 86 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' data: https://abri-production.s3.amazonaws.com https://abri-staging.s3.amazonaws.com https://abri-production.s3.eu-west-2.amazonaws.com https://abri-staging.s3.eu-west-2.amazonaws.com https://d2t1vdoabw4hm5.cloudfront.net https://d3jf2tu775mfgu.cloudfront.net *.backend-api.io *.googletagmanager.com *.google-analytics.com *.googleapis.com *.gstatic.com *.youtube.com *.vimeo.com *.8x8.com https://vercel.live https://vercel.com https://*.fonts.net https://*.civiccomputing.com http://widget.trustpilot.com https://*.browsealoud.com https://*.cqc.org.uk; frame-src *;- strict-transport-security
max-age=63072000; includeSubDomains; preload