embracefs.co.uk

.uk crawl

First seen 2026-05-27 · Last seen 2026-06-01 · ok HTTP/1.1 200 781 ms crawled 2026-05-30

US · 172.67.140.97 · AS13335 Cloudflare, Inc.

Reputation 86/100 dmarc partial coverage weak subdomain policy

Classifying

HTML metadata

Title
Embrace Financial Services | Mortgages and Protection
Description
Find ideal mortgages and protection products at Embrace Financial Services. Our UK advisers provide tailored advice for your needs.
Language
en-gb
Generator
Evosite
Canonical
https://www.embracefs.co.uk

Open Graph

url
https://www.embracefs.co.uk/
title
Embrace Financial Services | Mortgages and Protection
description
Find ideal mortgages and protection products at Embrace Financial Services. Our UK advisers provide tailored advice for your needs.

Technology

CDN
Cloudflare
Stack
PHP
Analytics
  • Google Analytics
  • Google Tag Manager

Third-party hosts loaded (4)

  • embracefs.s3.eu-west-2.amazonaws.com×9
  • rate-grid.meetparker.co.uk×1
  • www.google-analytics.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone
Address
St. Josephs Court, DN1 3NE, Woolwich Road, Devon, GB

DNS records live

NS
  • rudy.ns.cloudflare.com
  • tara.ns.cloudflare.com
MX
  • 0 embracefs-co-uk.mail.protection.outlook.com
TXT
  • 0ed1fe018a18b3534979b14ee885e75686debc8d1d
  • access-domain-verification=64730e371f0edd1b2505e36a89609d07e2e57af42984049a803824cab14b6207
Verified for
  • Apple
  • GlobalSign
  • Google
  • Microsoft 365
  • Zoom

Email authentication partial

SPF
v=spf1 include:spf.protection.outlook.com include:amazonses.com include:mail.briefyourmarket.com include:eu._netblocks.mimecast.com ip4:5.159.127.245 include:spf-uk.emailsignatures365.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; sp=none; rua=mailto:2l655bkp5y@rua.vfy.outboundverify.com; ruf=mailto:2l655bkp5y@ruf.vfy.outboundverify.com; pct=50; fo=1;
policy: quarantine · pct=50 · sp=none
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwr0WPU1Y9AJyy+3N7Gc28cI5M7icL0ZQnYV6T+WoBwmtbFOyXtMPeOCjj2BH5M5WvIebbsPqhy1bGx…
  • s1: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCphrs9beU3qHwvNZ3Wol5Lv9t6m9ANUZzXKiQsxKC65DTdwfOXoB+c6N4ZPuOgQWf3OLvUxYNJ56T6tUT256sDLO…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDZOkZWKwoJbaUAgBBV2K85t0XNKyImRCtW9qhe+PzTZTfRIHqgGn+rntEpmFUuvFsvKxVHzS6hSWfAhg9Dvt0gJM…
selectors probed

Certificate (current)

E7
from 2026-04-11 to 2026-07-10
Expires in 36 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.embracefs.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
accelerometer=(), camera=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), ambient-light-sensor=(), battery=(), document-domain=(), geolocation=(self)
x-content-type-options
nosniff
content-security-policy
style-src 'self' 'unsafe-inline' *.google.com *.googleapis.com *.gstatic.com https://c4b.online https://static.userback.io https://assets.investisdigital.com; img-src 'self' data: *.google-analytics.com https://evocms.s3.amazonaws.com *.doubleclick.net *.adfenix.com *.sfnix.com *.sfnix.net *.googleapis.com *.google.com *.google.co.uk *.google.ie *.gstatic.com *.ggpht.com *.googletagmanager.com *.facebook.com *.ytimg.com *.vimeocdn.com *.icims.com *.postcodeanywhere.co.uk *.your-move.co.uk *.reedsrains.co.uk *.convertize.io https://bat.bing.com https://bat.bing.net *.homefast.co.uk https://c4b.online https://assets.reapit.net/ https://script.hotjar.com/ *.contentsquare.net https://embracefs.s3.eu-west-2.amazonaws.com; frame-src 'self' *.doubleclick.net *.adfenix.com *.facebook.com *.google.com *.audioagent.com https://watchvid.io premium.giraffe360.com tour.giraffe360.com *.youtube.com https://youtu.be *.vimeo.com https://vimeo.com *.icims.com *.matterport.com *.vieweet.com https
strict-transport-security
max-age=31536000; preload, max-age=31536000; includeSubDomains

Links to (2)

Linked from (2)