croudace.co.uk
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
- Ads
-
- Google Ads (DoubleClick)
- Fonts
-
- Font Awesome
- Google Fonts
Third-party hosts loaded (7)
- 4979121.fls.doubleclick.net×1
- 53fb25f0954c4b8fb88ad1747e7ec706.js.ubembed.com×1
- fonts.googleapis.com×1
- t.spotler.com×1
- use.fontawesome.com×1
- widget.trustpilot.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- rd April 2023
DNS records live
- NS
-
- ns0.phase8.net
- ns1.phase8.net
- ns2.phase8.net
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 4 TXT records
autodesk-domain-verification=t6vEwrO1EA32kTlbm3LbMS=D25B2B317E9549377FFE4BFA04CB2B51B1C20C1424.06.20220ed1fe018a2166b864956c431f9f7c64a620bb97ad
- Verified for
-
- Apple
Email authentication strong
- SPF
-
v=spf1 include:_netblocks.mimecast.com include:emailus.freshservice.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; fo=1; ri=3600; rua=mailto:alerts@croudace.co.uk; ruf=mailto:alerts@croudace.co.uk;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 75 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- checked over plain HTTP
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' https://*.ubembed.com https://connect.facebook.net https://googleads.g.doubleclick.net https://t.spotler.com https://tags.srv.stackadapt.com https://u.heatmap.it https://widget.trustpilot.com https://www.google-analytics.com https://www.googletagmanager.com https://maps.googleapis.com https://maps.gstatic.com https://www.google.com https://www.gstatic.com https://snap.licdn.com; style-src 'self' 'unsafe-inline' https://*.ubembed.com https://widget.trustpilot.com https://fonts.googleapis.com https://use.fontawesome.com; font-src 'self' https://fonts.gstatic.com https://use.fontawesome.com data:; img-src 'self' data: blob: https://*.ubembed.com https://*.pages.ubembed.com https://www.google-analytics.com https://*.doubleclick.net https://u.heatmap.it https://app.unbounce.com https://www.googletagmanager.com https://www.google.com https://www.google.co.uk https://www.googleadservices.com https://www.facebook.com https://maps.googleapis