goodenergy.co.uk
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- cdn.shortpixel.ai×4
- unpkg.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- 123-Reg Limited t/a 123-reg
- Created
- 2001-10-21
- Expires
- 2026-10-21 153 days left
- Updated
- 2024-08-31
- Name servers
-
- ns-1398.awsdns-46.org.
- ns-1561.awsdns-03.co.uk.
- ns-410.awsdns-51.com.
- ns-744.awsdns-29.net.
DNS records live
- NS
-
- ns-1398.awsdns-46.org
- ns-1561.awsdns-03.co.uk
- ns-410.awsdns-51.com
- ns-744.awsdns-29.net
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 6 TXT records
amazonses:TFhdzbJKimdd1u4b5axVebUa4VJUoliUT4iX/8Kfor8=ca3-5f168d054a854325a4e2e429bc2030afca3-f575ebe47b1d4832aaeb8aff3135474a00D0D0000008efY=1TBPu0000000FLd00D20000000o0Bh=1TBTh00000000Uj4iwIDH0xOW1eBWFQvx5me/MxyU6qzdiMsI2YEqKWY6cUcB5GZrjQoKD6V1if3jlcGvgrzOHUYDGkW8bG6EEyXw==
- Verified for
-
- Airtable
- Atlassian
- GlobalSign
- OpenAI
- Zoho
Email authentication strong
- SPF
-
v=spf1 redirect=34th2liq._spf._d.mim.ecno all qualifier - DMARC
-
v=DMARC1; p=reject; sp=reject; rua=mailto:2c804b2a0502872@rep.dmarcanalyzer.com; ruf=mailto:2c804b2a0502872@for.dmarcanalyzer.com,mailto:dmarc@goodenergy.co.uk; fo=1;policy: reject (enforced) · sp=reject - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA03vskzEYHrFyG+uz7Jid8g2Ga0ho16TJGVF/60u0fg8gj/ZY50Gv3rx3mVIl6UBU+W3NUF/dZ49cxjfBPi… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDapm3qR7SE/mBJcnX27kJUe44taUrEFTh5LBvP5MU7ce0nh0Ij2qQEr0GDrIvyn0kC8vo5KmDacTI71ecF3KwkIk…
selectors probed - k2:
Certificate (current)
WE1
Expires in 68 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.goodenergy.co.uk gebusinessstaticprod01.blob.core.windows.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://urldefense.com/v3/ https://widget.trustpilot.com *.calendly.com calendly.com code.jquery.com *.cloudfront.net analytics.twitter.com *.ads-twitter.com *.sopro.io unpkg.com snap.licdn.com *.facebook.com *.facebook.net *.collect.igodigital.com *.shortpixel.ai https://googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://www.googletagmanager.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net api.websitecarbon.com *.w.org https://*.amplitude.com https://cdn.veritonic.com; connect-src 'self' ws: *.ideal-postcodes.co.uk api.websitecarbon.com https://sopro-personalisation.azurewebsites.net ipv4.podscribe.com *.linkedin.com https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https:/- strict-transport-security
max-age=31536000; includeSubDomains; preload