acecontrols.co.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
- Stack
- PHP
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (10)
- app.usercentrics.eu×3
- www.ace-ace.de×2
- api.usercentrics.eu×1
- js.hcaptcha.com×1
- www.ace-ace.cn×1
- www.ace-ace.com×1
- www.ace-ace.nl×1
- www.acecontrols.com×1
- www.acecontrols.jp×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns.udag.de
- ns.udag.net
- ns.udag.org
- MX
-
- 10 mxa-00858002.gslb.pphosted.com
- 10 mxb-00858002.gslb.pphosted.com
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a ip4:176.9.130.34 ip4:168.119.4.220 ip4:168.119.4.221 ip4:49.12.131.29 include:_spf.cmail.ondemand.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com,mailto:dmarcreports@stabilus.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com,mailto:dmarcreports@stabilus.compolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 39 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
font-src *.fontawesome.com *.googleapis.com https://www.gstatic.com fonts.gstatic.com fonts.googleapis.com *.hotjar.com *.zopim.com data: *.paypal.com *.paypalobjects.com *.typekit.net *.gstatic.com applepay.cdn-apple.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://fonts.gstatic.com https://fonts.bunny.net https://widgets.trustedshops.com at.alicdn.com userlike-cdn-umm.b-cdn.net assets.brevo.com www.acecontrols.co.uk www.ace-ace.de www.acecontrols.com www.ace-ace.com www.ace-ace.cn www.ace-ace.nl www.acecontrols.jp data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de- strict-transport-security
max-age=31536000; includeSubDomains; preload