hsjinformation.co.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Font Awesome
- Google Fonts
Third-party hosts loaded (6)
- cdn.jsdelivr.net×5
- cdnjs.cloudflare.com×4
- use.fontawesome.com×2
- www.googletagmanager.com×2
- fonts.googleapis.com×1
- fonts.gstatic.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.lexsynergy.net
- ns2.lexsynergy.us
- ns3.lexsynergy.info
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 13 TXT records
MS=ms71714930atlassian-domain-verification=3bTp3cxzROtpGXXVjQrDQXG5ZeTzJ89eavUCHECmQ06zkbWQcUctuN0RJi2zz2jiatlassian-domain-verification=mABOfdv/hKd4KyYXNTp94zXY5OsXxt1CeVqXGzCP2xQYO1bgqJ7pk7PMdg0yREyT_fztd5ktxb56c5540y33wgwrvtrps2khaccess-domain-verification=a827ae971ca2681b604866d5809bbd74c6ad2ad53f62697a109b84b865633ebesmartsheet-site-validation=Pxv_XhsgXacDOGZ4cEc12F1UgLOd10J1atlassian-sending-domain-verification=170563af-e3b2-49c7-b64d-ffb58acb51c4Octopus-d4fe3372-4b7f-4308-a4c0-8b39128a07a70ed1fe018af1ec190924e54603aa4e6e0ae9db6152atlassian-sending-domain-verification=c99d31af-5a91-43fb-859e-1ab8378f9f17MS=ms792588187f6yv7lzpd26v8l26z8rpmqmc1pg13mz_s0amirdnrjskx0g6cryb0gn2cu8tu54
Email authentication partial
- SPF
-
v=spf1 a mx include:eu._netblocks.mimecast.com include:sendgrid.net include:_spf.salesforce.com include:spf.e-shot.org include:spf.protection.outlook.com ip4:85.222.128.0/19 ip4:185.28.196.71 ip4:94.236.119.6 ip4:94.236.119.7 ip4:85.222.150.0/24 ip4:23.249.219.231 include:mktomail.com ip4:52.209.63.192/27 ip4:34.255.79.211 ip4:54.77.239.0 ip4:34.247.139.160 ip4:34.255.102.32/28 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; fo=1:d:s; rua=mailto:dmarc@hsjinformation.uriports.com; ruf=mailto:dmarc@hsjinformation.uriports.compolicy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0TpXv4PUg72UNNdOO3QePVLEzv7d+MZ5U4Ja1grEig1ano7Os6IrH9yvmCKD/ZhySsi0e1wC4yXxunpORs… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+tZxxWqHS32CldmAxPDIf4o06QgpU9NWVRYvp155w+lohj0SwQsIHteQn3OvrBP36jbpQAKCmRdN8uUKRSaxWO+…
selectors probed - s1:
Certificate (current)
R12
Expires in 21 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), display-capture=(), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(), gyroscope=(), hid=(), idle-detection=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), usb=(), web-share=(), xr-spatial-tracking=(), browsing-topics=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://use.fontawesome.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.gstatic.com https://cdn.cookie-script.com https://public.tableau.com https://static.hotjar.com https://script.hotjar.com https://*.hotjar.com https://snap.licdn.com https://munchkin.marketo.net https://munchkin.marketo.com https://*.marketo.net https://*.marketo.com https://go.hsjinformation.co.uk https://fast.wistia.com https://fast.wistia.net https://browser.sentry-cdn.com https://www.youtube.com https://s.ytimg.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://use.fontawesome.com https://go.hsjinformation.co.uk; img-src 'self' data: https: https://www.google-analytics.com https:- strict-transport-security
max-age=31622400; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-resource-policy
same-origin