bacp.co.uk

.uk crawl

First seen 2026-04-13 · Last seen 2026-05-18 · ok HTTP/1.1 200 7551 ms crawled 2026-05-06

IE · 23.102.12.43 · AS8075 Microsoft Corporation

Reputation 100/100

sector nonprofit type homepage

HTML metadata

Title
British Association for Counselling and Psychotherapy
Description
BACP is the professional association for members of the counselling professions in the UK. We exist for one simple reason - counselling changes lives
Language
en-GB

Technology

Analytics
  • Google Tag Manager
Fonts
  • Adobe Fonts

Third-party hosts loaded (4)

  • cdnjs.cloudflare.com×4
  • chart.googleapis.com×1
  • use.typekit.net×1
  • www.googletagmanager.com×1

Social

Registration

Registrar
Fasthosts Internet Ltd
Created
2000-08-22
Expires
2026-08-22 94 days left
Updated
2024-07-23
Name servers
  • ns1-02.azure-dns.com.
  • ns2-02.azure-dns.net.
  • ns3-02.azure-dns.org.
  • ns4-02.azure-dns.info.

DNS records live

NS
  • ns1-02.azure-dns.com
  • ns2-02.azure-dns.net
  • ns3-02.azure-dns.org
  • ns4-02.azure-dns.info
MX
  • 10 uk.mx1.mailanyone.net
  • 20 uk.mx2.mx25.net
  • 30 uk.mx3.mailanyone.net
  • 40 uk.mx4.mx25.net
TXT
  • MS=ms43972993
  • v=spf1 ip4:81.145.51.162 ip4:85.115.52.190 ip4:85.115.60.0/24 ip4:217.163.57.0/24 ip4:109.70.58.0/24 include:spf.protection.outlook.com include:spf.mailanyone.net include:customers.clickdimensions.com include:amazonses.com include:_spf.questback.net include:mailcontrol.com include:out.accesspaysuite.com include:_spf.elasticemail.com mx a ~all
  • cpn8krgvsntfh620t7dil4vo1b

Certificate (current)

Go Daddy Secure Certificate Authority - G2
from 2026-01-13 to 2027-02-08
Expires in 264 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.bacp.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https:; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; img-src * data:;connect-src * wss:
strict-transport-security
max-age=31536000; includeSubDomains

Links to (3)

Linked from (14)