elliottwood.co.uk
HTML metadata
Technology
- CDN
- Amazon CloudFront
Third-party hosts loaded (1)
- cdn.jsdelivr.net×1
Social
Contact
- Phone
- Address
- 55 Whitfield Street, W1T 4AH, London, England, United Kingdom
Registration
- Registrar
- 4D Data Centres Limited
- Created
- 1999-11-09
- Expires
- 2028-11-09 903 days left
- Updated
- 2019-10-03
- Name servers
-
- ns10.dnsmadeeasy.com.
- ns11.dnsmadeeasy.com.
- ns12.dnsmadeeasy.com.
- ns14.dnsmadeeasy.com.
- ns15.dnsmadeeasy.com.
DNS records live
- NS
-
- ns10.dnsmadeeasy.com
- ns11.dnsmadeeasy.com
- ns12.dnsmadeeasy.com
- ns13.dnsmadeeasy.com
- ns14.dnsmadeeasy.com
- ns15.dnsmadeeasy.com
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 12 TXT records
lr71rd94dh9dvdaedm9o3psg61uujnu7fbf4sg3st40vllq7lc7fm66chjnfkep81mjlg5330kk2f99rckkat1h0g3uvpnm8ms3i2u3gsophos-domain-verification=eb580baafd5127581652f54cb4c58d1de12c99f9f0vu6mbbb1qhaf4750pc8t8qcixyKO2yJiD1BCTdSQmZ4u5CJQcPRvNU2Qw9uzOxOrfgTpPNWykhHMn2Ka01dwlohN9qnpGuvL714eP9GNkmpjNw==lslmqlj53bu5u55h392g1uo2ufautodesk-domain-verification=I9xzKAfuMjAvXbroGz7Joo5j76oeq237knou3l74isiqsgg4neu2mvp35ssf83dqetrnl00r0ed1fe018a5ad122932cbd48139b6a056edaecd827
- Verified for
-
- Microsoft 365
- Zoom
Email authentication partial
- SPF
-
v=spf1 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com include:spf.uk.exclaimer.net include:servers.mcsv.net ip4:35.156.0.138 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
E7
Expires in 76 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src * https: data: blob: android-webview-video-poster: 'unsafe-inline' 'unsafe-eval'; object-src 'none'; frame-ancestors 'self';- strict-transport-security
max-age=31536000; includeSubDomains