ecology.co.uk

.uk crawl

First seen 2026-04-22 · Last seen 2026-05-15 · ok HTTP/1.1 200 1684 ms crawled 2026-05-15

US · 141.193.213.20 · AS209242 Cloudflare London, LLC

Reputation 94/100 dmarc monitor-only

Classifying

HTML metadata

Title
Ethical Savings & Mortgages at Ecology Building Society
Description
At Ecology, we're building a greener society through sustainable residential & commercial mortgages funded by ethical savings accounts.
Language
en-GB
Generator
WP Rocket 3.20.1.2
Canonical
https://www.ecology.co.uk/

Open Graph

url
https://www.ecology.co.uk/
title
Ethical Savings & Mortgages at Ecology Building Society
locale
en_GB
site name
Ecology Building Society
description
At Ecology, we're building a greener society through sustainable residential & commercial mortgages funded by ethical savings accounts.

Technology

CDN
Cloudflare
CMS
WordPress
Analytics
  • Google Tag Manager
  • Plausible
Ads
  • Meta Pixel
Cookie consent
  • OneTrust
Fonts
  • Google Fonts
Third-party hosts loaded (10)
  • fonts.googleapis.com×5
  • ajax.googleapis.com×3
  • cdn.datatables.net×3
  • fonts.gstatic.com×2
  • smartmoneypeople.com×2
  • bat.bing.com×1
  • cdn-ukwest.onetrust.com×1
  • connect.facebook.net×1
  • plausible.io×1
  • www.googletagmanager.com×1

Social

Contact

Phone

Registration

Registrar
Team Blue Internet Services UK Limited t/a Team Blue Internet Services Limited t/a names.co.uk
Created
1997-03-18
Expires
2029-03-18 1032 days left
Updated
2026-03-18
Name servers
  • karl.ns.cloudflare.com.
  • rafe.ns.cloudflare.com.

DNS records live

NS
  • karl.ns.cloudflare.com
  • rafe.ns.cloudflare.com
MX
  • 10 eu-smtp-inbound-1.mimecast.com
  • 10 eu-smtp-inbound-2.mimecast.com
TXT
Show 5 TXT records
  • rj2sovsvobg65fri1j909difet.
  • 00DJ9000000QSAE=1TBPx000000046r
  • 63e3m92k9sqo6q1v33b19nj5en
  • fvl3ppfl8l0hdpb5vo7nu2hh9a
  • intacct-esk=FF59B7114F81EF21E0533806410A5C5C
Verified for
  • Atlassian
  • Google
  • Microsoft 365

Email authentication partial

SPF
v=spf1 mx include:relay.mailchannels.net include:mailgun.org include:eu._netblocks.mimecast.com include:amazonses.com include:_spf.intacct.com include:spf.protection.outlook.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none; rua=mailto:91c5cbba8ae8815@rep.dmarcanalyzer.com; ruf=mailto:91c5cbba8ae8815@for.dmarcanalyzer.com; fo=1;
policy: none (monitoring only)
DKIM
  • k2: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6MadGUA/kpBbAKtv7FEvNcPB5o/Ub0Dfu7iKUuKNVtdPMuuxr3iEWifAa+cGSdJyq3IkZvuR06tt92T1ZL…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC94lVsoH+FSl28MKwfyiiLnJH+iXYlf9TYmygDVi1vuQ7mZQfQCHTvWhR9tq6GGyxPCEhgYf8cWKBCEgG1/DitHW…
selectors probed

Certificate (current)

WE1
from 2026-03-22 to 2026-06-21
Expires in 31 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.ecology.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
sameorigin
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-eval' *.contentsquare.net http://*.hotjar.com:* https://*.hotjar.com:* ws://*.hotjar.com wss://*.hotjar.com https://api.mapbox.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.contentsquare.net https://plausible.io https://cdn-ukwest.onetrust.com https://unpkg.com https://player.vimeo.com https://acsbapp.com https://*.data-crypt.com https://*.websites.data-crypt.com https://*.cloudflareinsights.com https://app.vwo.com https://dev.visualwebsiteoptimizer.com https://platform.twitter.com https://cdn.polyfill.io https://www.gstatic.com https://cc.cdn.civiccomputing.com https://cdnjs.cloudflare.com https://www.authy.com https://v1.addthis.com https://www.authy.com/form.authy.min.js https://maps.googleapis.com https://graph.facebook.com https://widgets.pinterest.com https://api-public.addthis.com https://m.addthisedge.com https://m.addthis.com https://s7.addthis.com https://tagmanager.google.com https://s.ytimg.com https://www.youtube.com https://script.hotja
strict-transport-security
max-age= 31536000; includeSubDomains; preload

Links to (6)

Linked from (2)