exetersciencepark.co.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- fonts.gstatic.com×3
- api.transpond.io×1
- cdn-cookieyes.com×1
- cdnjs.cloudflare.com×1
- maps.googleapis.com×1
- px.ads.linkedin.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- hal.ns.cloudflare.com
- olivia.ns.cloudflare.com
- MX
-
- 0 exetersciencepark-co-uk.mail.protection.outlook.com
- TXT
-
103stcd23a453oerkr1a2vns8j
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a ip4:52.51.79.206 ip4:167.89.65.77 ip4:185.56.87.9 include:spf.ourmailsender.com include:spf.protection.outlook.com include:_spf.nexudus.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+W3oP27D2lZxhqbQxPrpJKbeFHl5pWJFAnaMMK2oxyPoi5pMd0y2Wn/rAdoAm853e4ztHgTJH/oa/h3cI78… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv5cd0FFy/kvYL/+65P3mM50ghBTQjZjLFH1obBDVMHk0SCG8ONKpNSWHQq8CK/SZ0ETr2YoNqP0FrnC3CJ… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC43W0zJttZqgX+TjZZI7a7gCu6HvMY8JW6Lru+naTWwFxb1WOybAoBHT9H2Qc+Vq5C3KSphzVmA1a58kFSKbsET+…
selectors probed - selector1:
Certificate (current)
R12
Expires in 75 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(self 'https://abc.example.com' 'https://pqr.example.com'), midi=(), sync-xhr=(), accelerometer=(), gyroscope=(), magnetometer=(), camera=(), microphone=(), fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
default-src https: 'unsafe-eval' 'unsafe-inline' 'self'; object-src 'self'; font-src https: data: 'self' http: fonts.googleapis.com themes.googleusercontent.com; connect-src https: wss: 'self'; img-src https: data: 'self' http: *.gravatar.com; worker-src blob: https: 'self' 'unsafe-inline' 'unsafe-eval'; media-src https: blob: 'self'; frame-src https: blob: 'self'; style-src https: 'unsafe-eval' 'unsafe-inline' 'self' http: fonts.googleapis.com- strict-transport-security
max-age=31536000; includeSubDomains; preload
exetersciencepark.co.uk