firstcentralgroup.com

.com crawl

First seen 2026-05-02 · Last seen 2026-05-20 · ok HTTP/1.1 200 2783 ms crawled 2026-05-08

GB · 213.167.74.30 · AS13173 Foreshore Limited

Reputation 100/100

Classifying

HTML metadata

Title
1st Central Group
Description
Welcome to 1st Central Group, a fast-growing UK insurer and innovator in data, delivering market-leading motor insurance, underwriting, distribution, finance and technology.
Language
en
Canonical
https://www.firstcentralgroup.com/

Technology

Analytics
  • Google Tag Manager
Cookie consent
  • OneTrust
Fonts
  • Google Fonts

Third-party hosts loaded (5)

  • assets.adobedtm.com×2
  • cdn.cookielaw.org×2
  • fonts.googleapis.com×2
  • fonts.gstatic.com×1
  • www.googletagmanager.com×1

Social

Contact

Address
st Central Group.Any data shown is accurate as of 31/12/2024

Registration

Registrar
Tucows Domains Inc.
Created
2015-07-22
Expires
2026-07-22 62 days left
Updated
2025-08-05
Name servers
  • dns41.cloudns.net
  • dns42.cloudns.net
  • dns43.cloudns.net
  • dns44.cloudns.net

DNS records live

NS
  • dns41.cloudns.net
  • dns42.cloudns.net
  • dns43.cloudns.net
  • dns44.cloudns.net

Email authentication no MX

SPF
v=spf1 -all
strict (-all)
DMARC
v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s;rua=mailto:b6c48d81d6@rua.easydmarc.us; ruf=mailto:b6c48d81d6@ruf.easydmarc.us; fo=1
policy: reject (enforced) · sp=reject
DKIM
Show 12 DKIM selectors
  • default: v=DKIM1; p=
  • google: v=DKIM1; p=
  • selector1: v=DKIM1; p=
  • selector2: v=DKIM1; p=
  • k1: v=DKIM1; p=
  • k2: v=DKIM1; p=
  • mail: v=DKIM1; p=
  • dkim: v=DKIM1; p=
  • s1: v=DKIM1; p=
  • s2: v=DKIM1; p=
  • mxvault: v=DKIM1; p=
  • smtpapi: v=DKIM1; p=
selectors probed

Certificate (current)

Sectigo RSA Domain Validation Secure Server CA
from 2025-05-27 to 2026-06-08
Expires in 18 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.firstcentralgroup.com/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
default-src 'self' 'unsafe-inline' data: *.1stcentralinsurance.com *.analytics-egain.com *.2o7.net *.adobedtm.com *.bootstrapcdn.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.egain.cloud *.facebook.com *.facebook.net *.feefo.com *.fontawesome.com *.frontify.com *.github.io *.google.co.uk *.google.com *.googleadservices.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.instagram.com *.klick2contact.com *.omguk.com *.opendns.com *.optimizely.com *.sessioncam.com *.trustpilot.com *.twitter.com *.youtube.com *.youtube-nocookie.com *.ytimg.com *.cookielaw.org *.gbqofs.com *.pure.cloud *.onetrust.com *.amazonaws.com *.bing.com *.gstatic.com *.jsdelivr.net *.tiktok.com *.contentsquare.net *.contentsquare.com *.gbss.io adobedc.demdex.net edge.adobedc.net; frame-ancestors 'self' *.firstcentralgroup.com; worker-src 'self' blob:; connect-src 'self' wss://*.pure.cloud api://*.pure.cloud *.pure.cloud *.firstcentralgroup.com *.omguk.com *.contentsquare.net *.contentsq
strict-transport-security
max-age=31536000; includeSubDomain

Links to (2)

Linked from (1)