cormarcarpets.co.uk
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- fonts.googleapis.com×3
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
Contact
- Address
- Brookhouse Mill, Holcombe Road, BL8 4HR, Bury, Greater Manchester, United Kingdom
Registration
- Registrar
- Zen Internet Limited
- Created
- 2000-03-07
- Expires
- 2027-03-07 290 days left
- Updated
- 2026-01-27
- Name servers
-
- ns0.zen.co.uk.
- ns1.zen.co.uk.
DNS records live
- NS
-
- ns0.zen.co.uk
- ns1.zen.co.uk
- MX
-
- 5 eu-smtp-inbound-1.mimecast.com
- 5 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 5 TXT records
LJFyJGePxvTHq1vQ1ce232Uk1GbD5G1rbiVyVakUPNoOPljGBLiPlIGKKK1gWVAB9hvigtixbp1kX7/lQkiw7Q==sophos-domain-verification=ed03f5a3795c6026819643847af2338ab8fa801443ce8dc145390b653703d5320ed1fe018a06555c07bbd2436993b300be15cb4b68sophos-domain-verification=f437dc2c4bcb8623069a9bf563e8507ca15af55bmandrill_verify.h0Lphk74JCsYxDFF-AIpjw
- Verified for
-
- Apple
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:eu._netblocks.mimecast.com include:u1535540.wl041.sendgrid.net include:u14098017.wl018.sendgrid.net include:mail.zendesk.com include:_spf.tacklephishing.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=75; rua=mailto:rua@cormarcarpets.co.uk;policy: reject (enforced) · pct=75 - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnhyAlKBD8HU9QKhdaDo1P6/OhufyJLjBrnpoLDUP3NS/mzDvkPmT4vwzjY2p/dxKoknfAEwMXREMN+L07c… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDSxtlm60JucnhIcVfH47iJh99ItioAu2wbSyu28mvffUvKpD8krVarz7sSZNRtDsheRjvmK6R/ooaI+BxfHz8JDh…
selectors probed - k2:
Certificate (current)
R12
Expires in 77 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(),autoplay=(),camera=(),display-capture=(),encrypted-media=(),fullscreen=(),gamepad=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),sync-xhr=(self),usb=(),screen-wake-lock=(),web-share=(),xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://static.hotjar.com https://connect.facebook.net https://s.pinimg.com https://bat.bing.com https://survey.survicate.com https://googleads.g.doubleclick.net https://*.clarity.ms https://ct.pinterest.com https://script.hotjar.com; script-src-elem 'self' 'unsafe-inline' https://www.google-analytics.com https://www.googletagmanager.com https://static.hotjar.com https://connect.facebook.net https://s.pinimg.com https://bat.bing.com https://survey.survicate.com https://*.clarity.ms https://googleads.g.doubleclick.net https://ct.pinterest.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://script.hotjar.com https://api.ideal-postcodes.co.uk https://pagead2.googlesyndication.com https://*.moatads.com https://*.addthis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://ad.doubleclick.net https://bat.bing.com https://www.facebook.com https://w- strict-transport-security
max-age=31536000; includeSubDomains; preload