bloomsburyprofessionalonline.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (5)
- res.cloudinary.com×11
- cdnjs.cloudflare.com×2
- cdn-ukwest.onetrust.com×1
- www.googletagmanager.com×1
- www.recaptcha.net×1
Registration
- Registrar
- 123-Reg Limited
- Created
- 2009-08-21
- Expires
- 2026-08-21 92 days left
- Updated
- 2025-08-22
- Name servers
-
- ns-1388.awsdns-45.org
- ns-159.awsdns-19.com
- ns-1733.awsdns-24.co.uk
- ns-741.awsdns-28.net
DNS records live
- NS
-
- ns-1388.awsdns-45.org
- ns-159.awsdns-19.com
- ns-1733.awsdns-24.co.uk
- ns-741.awsdns-28.net
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 267 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak content type protection
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),autoplay=(),camera=(),encrypted-media=(self),fullscreen=*,geolocation=*,gyroscope=(),interest-cohort=(),magnetometer=(),microphone=(),midi=(),sync-xhr=*,usb=(),xr-spatial-tracking=()- x-content-type-options
strict-origin-when-cross-origin- content-security-policy
worker-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.vjs.zencdn.net *.sspbloomsbury.co.uk *.photoninfotech.com *.googletagmanager.com *.google.com *.facebook.net *.gstatic.com *.test.semantico.net *.recaptcha.net *.cloudinary.com *.onetrust.com *.brightcove.net *.cloudflare.com *.googleapis.com *.star.saas.semcs.net *.3playmedia.com *.zscloud.net; frame-src 'self' *.youtube.com *.brightcove.net *.recaptcha.net *.photoninfotech.com *.sspbloomsbury.com *.worldbank.org *.googletagmanager.com *.live.com *.google.com; object-src 'self'; frame-ancestors 'self';- strict-transport-security
max-age=31536000; includeSubDomains; preload