accurx.nhs.uk
HTML metadata
Technology
- CMS
- Next.js
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- produkstaticassets.blob.core.windows.net×13
- fonts.googleapis.com×2
- fonts.gstatic.com×1
- www.nhsapp.service.nhs.uk×1
DNS records
- CNAME
-
- accurx-thirdparty-nhs-uk.accurx.com
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
ZeroSSL RSA DV SSL CA 2
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
Deny- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' https://produkstaticassets.blob.core.windows.net https://www.nhsapp.service.nhs.uk https://*.accurx.com/ https://browser.sentry-cdn.com data: ; child-src 'self'; style-src 'self' 'unsafe-inline' https://produkstaticassets.blob.core.windows.net https://fonts.googleapis.com https://ajax.aspnetcdn.com; font-src 'self' 'unsafe-inline' https://ajax.aspnetcdn.com/ajax/ https://fonts.gstatic.com https://assets.nhs.uk data:; img-src 'self' https://produkstaticassets.blob.core.windows.net https://www.gstatic.com/images/ https://browser-update.org data:; connect-src 'self' https://*.accurx.com/ https://api.rudderlabs.com https://accurx-dataplane.rudderstack.com https://app.getsentry.com https://sentry.io https://o198389.ingest.sentry.io wss://bs-local.com:* https://js.monitor.azure.com/scripts/b/ai.config.1.cfg.json https://js.monitor.azure.com/ https://dc.services.visualstudio.com/v2/track; worker-src 'self'; form-action 'self'; frame-src 'sel- strict-transport-security
max-age=63072000; includeSubDomains; preload