cerelac.co.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
Social
Registration
- Registrar
- Nom-IQ Limited t/a Com Laude
- Created
- 2015-04-21
- Expires
- 2027-04-21 335 days left
- Updated
- 2026-03-22
- Name servers
-
- amsdns1.nestle.com.
- aoadns1.nestle.com.
- ctrdns1.nestle.com.
- eurdns1.nestle.com.
DNS records live
- NS
-
- amsdns1.nestle.com
- aoadns1.nestle.com
- ctrdns1.nestle.com
- eurdns1.nestle.com
- Verified for
-
Email authentication no MX
- SPF
-
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 30 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.sessioncam.com *.cloudfront.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.cerelac.co.uk *.addtoany.com *.adimo.co *.amazon-adsystem.com *.amazonaws.com *.bazaarvoice.com *.betrad.com *.cdns.eu1.gigya.com *.cloudflare.com *.cloudfront.net *.cookielaw.org *.cookiepro.com *.doubleclick.net *.evidon.com *.facebook.net *.force.com *.fusepump.com *.gigya.com *.google-analytics.com *.google.co.uk *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.hypemarks.com *.iesnare.com *.igodigital.com *.jquery.com *.jsdelivr.net *.krxd.net *.nestle.co.uk *.newrelic.com *.nr-data.net *.onetrust.com *.pinimg.com *.polyfill.io *.salesforce.com *.salesforceliveagent.com *.serving-sys.com *.sessioncam.com *.sitepreview.ws *.yimg.com *.youtube.com data-eu.cerelac.co.uk *.usabilla.com *.ownid.com *.nestle.com *.segmentapis.com *.segment.com *.segment.io; style-src 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com https://cdnjs.cloudflare.com brand-eco- strict-transport-security
max-age=1000, max-age=300