cafre.ac.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- www.googletagmanager.com×3
- cdn.jsdelivr.net×2
- fonts.googleapis.com×2
- cookie-cdn.cookiepro.com×1
Social
DNS records live
- NS
-
- ns1.bb-online.net
- ns1.nics.gov.uk
- ns2.bb-online.org
- ns2.nics.gov.uk
- ns3.bb-online.uk
- ns4.bb-online.biz
- MX
-
- 0 cafre-ac-uk.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
MS=ms71926830MS=ms70388661k97dnlkq9w1kgdk3xczfx5pwbm2qk45ksophos-domain-verification=598ed7b7c0b3c623a6a213c741f65d5d8f2da6787506268gwvnqb7gq3gc5t2rppsxb4hllwMTkLeWL1Enb+SrF4zogWuH9BgE66XSTfIRgGVECMsQD3S8nvlMrSrf3UayR3EvBjGwUhCpeLinY/qQ+yO/ajA==
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:89.185.150.155 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=0; sp=none; adkim=r; aspf=r; rua=mailto:dmarc-rua@finance-ni.gov.uk,mailto:7c8cbf1d@inbox.ondmarc.com; ruf=mailto:7c8cbf1d@inbox.ondmarc.com; fo=1; ri=3600policy: quarantine · pct=0 · sp=none - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 45 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff, nosniff- content-security-policy
script-src 'unsafe-eval' 'self' 'unsafe-inline' *.cookiepro.com *.googletagmanager.com *.google.com *.google-analytics.com *.gstatic.com *.googleapis.com cdn.jsdelivr.net polyfill.io sc-static.net *.snapchat.com *.hotjar.com *.newrelic.com;, script-src 'unsafe-eval' 'self' 'unsafe-inline' *.cookiepro.com *.googletagmanager.com *.google.com *.google-analytics.com *.gstatic.com *.googleapis.com cdn.jsdelivr.net polyfill.io sc-static.net *.snapchat.com *.hotjar.com *.newrelic.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload