caffynsplc.co.uk
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (7)
- bluesky-cogcms-prodb.cdn.imgeng.in×15
- bluesky.sirv.com×6
- ajax.googleapis.com×1
- bluesky-cogstock.cdn.imgeng.in×1
- cdnjs.cloudflare.com×1
- stackpath.bootstrapcdn.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns51.domaincontrol.com
- ns52.domaincontrol.com
- MX
-
- 10 mx0.123-reg.co.uk
- 20 mx1.123-reg.co.uk
Email authentication strong
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:788eaa66e944948@rep.dmarcanalyzer.com; ruf=mailto:788eaa66e944948@for.dmarcanalyzer.com; fo=1;policy: reject (enforced) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvEcAFEhHQmskFgMbCaaUtRfLVJERXXd5y7jTtaHzoFWTzUcpgVyXKAZ8qiVeboEAonv7Y4W1rOuIQSCveX… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3Do9n1uAKTSlNpg9Q03GZwOTgZh6M4VY5dXf74gckvRn1S2nC+87jNhlCH2jxwFRaKrmb1rMowwL/k86h2…
selectors probed - s1:
Certificate (current)
R12
Expires in 28 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' bluesky.sirv.com *.bing.com *.codeweavers.net *.facebook.com *.google.com *.liveperson.net *.lpsnmedia.net newvehicle.com *.swipetospin.com *.twitter.com *.youtube.com *.loyaltyevent.co.uk sibautomation.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://consent.cookiebot.com/ https://cdn.matomo.cloud/ https://consentcdn.cookiebot.com/ *.autoconverse.co.uk bluesky.sirv.com *.bing.com *.bootstrapcdn.com cast.cogcast.co.uk *.calltracks.com *.cargurus.com cc.cdn.civiccomputing.com cdnjs.cloudflare.com cdn.datatables.net *.matomo.cloud *.codeweavers.net *.doubleclick.net embedsocial.com *.facebook.net *.fontawesome.com g3-web.s3.eu-west-2.amazonaws.com *.google.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.gubagoo.io *.hotjar.com *.impel.io *.judgeservice.com *.jquery.com *.jsdelivr.net *.lifeonshow.tv *.liveperson.net *.livevacancies.co.uk *.lpsnmedia.net *.mediahawk.co.uk newvehicle.com newvehicle.info media-player.aos.tv *- strict-transport-security
max-age=31536000