avantitravelinsurance.co.uk
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- fonts.googleapis.com×3
- dxcdkie9wax5t.cloudfront.net×2
- fonts.gstatic.com×2
- cdn-pci.optimizely.com×1
- gmpg.org×1
- widget.trustpilot.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- rd RoadNorthampton, NN4 7YB0800
Registration
- Registrar
- Gandi
- Created
- 2009-09-14
- Expires
- 2026-09-14 116 days left
- Updated
- 2025-08-10
- Name servers
-
- elly.ns.cloudflare.com.
- maciej.ns.cloudflare.com.
DNS records live
- NS
-
- elly.ns.cloudflare.com
- maciej.ns.cloudflare.com
- MX
-
- 1 eu-smtp-inbound-1.mimecast.com
- 2 eu-smtp-inbound-2.mimecast.com
- TXT
-
0ed1fe018a9f40b5ac7be349a5b6a503ad38afe154amb8b28ako0ir328ncs7pcru9g
- Verified for
-
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:_netblocks.mimecast.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:tp3hd674k0@rua.powerdmarc.com,mailto:enquiries@avanti.co.uk,mailto:dmarc_agg@dmarc.everest.email; ruf=mailto:tp3hd674k0@ruf.powerdmarc.com,mailto:enquiries@avanti.co.uk,mailto:dmarc_fr@dmarc.everest.email; pct=100; fo=1;policy: quarantine - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0uxSJpybEMWeowD3qK79+0Nm47wvGWc5tGwt5q67gGuwUZi6MkBe0M7lcf6RMjzKVdYulLsbvR7FMZ9YpI… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIeZV+zjZMpJsk5yxogTyW1LMcKp/rkVBR/nUszpqp6G5OCPAuY0HvEsBbbVLUeLQ1IgziMb9AtJdgGQDgm8Xf7Y…
selectors probed - s1:
Certificate (current)
WE1
Expires in 79 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
camera=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src https: data: blob: 'unsafe-inline' 'unsafe-eval' i0.wp.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.niceincontact.com static.zdassets.com staysure-prod.boost.ai *.smooch.io staysure.boost.ai *.zendesk.com tag4arm.azureedge.net berrythompson.innocraft.cloud *.tradedoubler.com api.smooch.io *.hotjar.com *.onetrust.com www.google-analytics.com bat.bing.com googleads.g.doubleclick.net *.contentsquare.net unpkg.com www.tag4arm.com connect.facebook.net logx.optimizely.com *.mention-me.com tag.mention-me.com cdn-pci.optimizely.com dxcdkie9wax5t.cloudfront.net analytics.freespee.com widget.trustpilot.com www.googletagmanager.com static.zdassets.com v2.zopim.com ajax.googleapis.com cdnjs.cloudflare.com cdn.datatables.net script.infinity-tracking.com *.infinity-tracking.com ict.infinity-tracking.net; font-src data: 'self' *.hotjar.com fonts.gstatic.com; img-src data: blob: 'self' *.niceincontact.com staysure.zendesk.com *.zendesk.com www.gravatar.com static.zdassets.com *- strict-transport-security
max-age=31536000; includeSubdomains