craftedco.uk
HTML metadata
Technology
- Server
- Microsoft-IIS
- Fonts
-
- Adobe Fonts
- Google Fonts
Third-party hosts loaded (7)
- cdn.jsdelivr.net×5
- fonts.googleapis.com×3
- 2m-office.com×1
- cdnjs.cloudflare.com×1
- code.jquery.com×1
- fonts.gstatic.com×1
- use.typekit.net×1
Social
Contact
Registration
- Registrar
- Krystal Hosting Ltd
- Created
- 2022-02-04
- Expires
- 2027-02-04 260 days left
- Updated
- 2022-02-10
- Name servers
-
- dion.ns.cloudflare.com.
- gracie.ns.cloudflare.com.
DNS records live
- NS
-
- dion.ns.cloudflare.com
- gracie.ns.cloudflare.com
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 5 TXT records
0ed1fe018aabbfd209e45f4769a3c4c11ca3ddd542MS=ms94864354atlassian-domain-verification=i3v7rLLoig/oPDHt2AmU7bPUDkqSyUJlElajaINYOKLvS96c5ZgefN3m5tsnZJt6google-site-verification=IjUQROJv1TzSMMBcKeruf9AJHBiPyKHv-EAscWrQZpkv=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email;
Email authentication weak
- SPF
-
v=spf1 include:eu._netblocks.mimecast.com include:servers.mcsv.net ip4:149.72.194.127 ip4:195.224.151.68 -allstrict (-all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyTUchziRzO3UtCbf9yM4K9BqNm5F67aurCeuhHvb3zLOikVO4WVXNlJOnh1kZquNWCIfhPlxQafNgZNRrd… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC52OtBmScBd6eZgJNfR27G1MB6aREpbiiKfseD8kgsgigHAuKH3wvCaqSvPAh0IR8WSyiv5ngdaUZUqafGNPkUqJ…
selectors probed - s1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 97 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' data: blob: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: blob: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:;- strict-transport-security
max-age=31536000; includeSubDomains