fasmembers.org.uk

.uk crawl

First seen 2026-04-30 · Last seen 2026-05-19 · ok HTTP/1.1 200 3337 ms crawled 2026-05-08

US · 104.18.20.164 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Welcome to the Financial Assistance Scheme (FAS) Members Website
Description
Website used by the Financial Assistance Scheme (FAS) members to register or login for online services to manage their pensions. This scheme is managed by the Pension Protection Fund (PPF).
Language
en

Technology

CDN
Cloudflare
CMS
Joomla

Third-party hosts loaded (1)

  • www.google.com×1

Social

Registration

Registrar
123-Reg Limited t/a 123-reg
Created
2016-04-13
Expires
2027-04-13 327 days left
Updated
2025-04-14
Name servers
  • lynn.ns.cloudflare.com.
  • sofia.ns.cloudflare.com.

DNS records live

NS
  • lynn.ns.cloudflare.com
  • sofia.ns.cloudflare.com
MX
  • 30 eu-smtp-inbound-1.mimecast.com
  • 30 eu-smtp-inbound-2.mimecast.com

Email authentication strong

SPF
v=spf1 include:spf-uk.emailsignatures365.com include:eu._netblocks.mimecast.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc-rua@ppf.co.uk,mailto:YTdWoZNKKPh@dmarc-rua.mailcheck.service.ncsc.gov.uk; ruf=mailto:dmarc-ruf@ppf.co.uk; fo=1; sp=reject;
policy: reject (enforced) · sp=reject
DKIM
no key found at common selectors

Certificate (current)

DigiCert EV RSA CA G2
from 2025-07-04 to 2026-08-05
Expires in 76 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.fasmembers.org.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; script-src-elem 'self' data: 'unsafe-inline' https://*.ppfmembers.org.uk/ https://statse.webtrendslive.com https://www.promisejs.org https://www.googletagmanager.com https://www.gstatic.com https://www.google.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; img-src 'self' https://i.ytimg.com blob: data: https://statse.webtrendslive.com; font-src 'self'; connect-src 'self' https://region1.google-analytics.com; frame-src 'self' https://www.research.net/ https://www.youtube.com https://www.google.com; frame-ancestors 'self'; form-action 'self'
strict-transport-security
max-age=31536000; includeSubDomains

Links to (7)

Linked from (2)