bcsa.org.uk

.uk crawl

First seen 2026-04-12 · Last seen 2026-05-19 · ok HTTP/1.1 200 1094 ms crawled 2026-05-04

GB · 20.50.106.247 · AS8075 Microsoft Corporation

Reputation 100/100

Classifying

HTML metadata

Title
Home | British Constructional Steelwork Association | BCSA
Description
Home page of the British Constructional Steelwork Association website - BCSA - links to news, events, directory listings and much more
Language
en
Canonical
https://www.bcsa.org.uk/

Technology

Server
Microsoft-IIS

Third-party hosts loaded (2)

  • cc.cdn.civiccomputing.com×1
  • www.google.com×1

Social

Contact

Email
Phone
Address
British Constructional Steelwork Association4 Whitehall CourtWestminsterLondon SW1A 2ES

Registration

Registrar
Cloudflare, Inc.
Created
1997-02-26
Expires
2027-02-26 281 days left
Updated
2026-01-27
Name servers
  • lana.ns.cloudflare.com.
  • plato.ns.cloudflare.com.

DNS records live

NS
  • lana.ns.cloudflare.com
  • plato.ns.cloudflare.com
MX
  • 10 bcsa-org-uk.mail.protection.outlook.com
TXT
  • v=spf1 include:spf.protection.outlook.com ip4:149.72.95.143 ip4:167.89.63.37 include:sendgrid.net ip4:159.65.28.58 include:spf.sendinblue.com include:mailgun.org include:spf.mandrillapp.com include:eu._netblocks.mimecast.com -all
  • 0ed1fe018af1f2119d5c034435a365ad
Verified for
  • Microsoft 365

Certificate (current)

R12
from 2026-03-10 to 2026-06-08
Expires in 19 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://bcsa.org.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
Deny
x-content-type-options
nosniff
content-security-policy
default-src 'self';script-src 'self' 'nonce-f6qu1wX9Zy7wmxoKxLiivTVy' kit.fontawesome.com/615688e97c.js https://cc.cdn.civiccomputing.com https://www.googletagmanager.com https://www.google.com https://player.vimeo.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;img-src 'self' data: https://www.googletagmanager.com https://www.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://maps.gstatic.com https://maps.googleapis.com;frame-src 'self' https://maps.google.com https://www.google.com https://player.vimeo.com https://www.youtube.com;font-src 'self' ka-f.fontawesome.com https://fonts.gstatic.com;connect-src 'self' ka-f.fontawesome.com https://maps.googleapis.com https://apikeys.civiccomputing.com https://region1.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://www.google.com/recaptcha/;report-uri /csp/
strict-transport-security
max-age=31536000

Links to (5)

Linked from (2)