jewson.co.uk

.uk crawl

First seen 2026-04-14 · Last seen 2026-05-15 · ok HTTP/1.1 200 1632 ms crawled 2026-05-07

US · 45.223.116.181 · AS19551 Incapsula Inc

Reputation 100/100

sector home type homepage

HTML metadata

Title
Jewson Builders Merchants, Timber Merchants & Tool Hire
Description
The UK's leading chain of builders merchants. Supplier of building materials & equipment, supplies, tools & timber with over 400 branches branches across the UK.
Language
en
Canonical
https://www.jewson.co.uk/

Technology

Server
*
CMS
WordPress
Fonts
  • Adobe Fonts

Third-party hosts loaded (3)

  • use.typekit.net×4
  • assets.adobedtm.com×1
  • cc.cdn.civiccomputing.com×1

Social

Contact

Phone
Address
STARK Building Materials UK Limited Trading as Jewson </br>Merchant House, Binley Business Park, Harry Weston Road, Coventry, CV3 2TT

Registration

Registrar
EuroDNS SA
Created
1996-02-20
Expires
2027-02-20 275 days left
Updated
2026-02-13
Name servers
  • ns-a.eurodns.com.
  • ns-b.eurodns.org.
  • ns-c.eurodns.eu.
  • ns-d.eurodns.biz.

DNS records live

NS
  • ns-a.eurodns.com
  • ns-b.eurodns.org
  • ns-c.eurodns.eu
  • ns-d.eurodns.biz
MX
  • 0 jewson-co-uk.mail.protection.outlook.com
TXT
Show 9 TXT records
  • y7k6gmBbjRJw9oKiptNx7QX86vKuuFnfNWMrRyVY5RVg+Q53VymxsX0rZu8LGJTvcJ7i8Ds+TRypqPkIPWh6Bg==
  • gnl4rzvj9tdskk1mlls7dr63jm6kqqh2
  • nfpqpqcy9zrl81zwb0vg06pf0fcly07n
  • x4wya8n.ng.impervadns.net
  • 5qxr6gwb5b8qdcw2n9qgcc1x8ktlxcvw
  • 1pxqklfhcb1qm93m9tvchvtplm0xyqb8
  • 7tqlxfy2nz1gf7bt3qmpz8hnw4vx2z05
  • wyiuitj.x.incapdns.net
  • 3sptxv6705j8w40gv1rgt2t9b4z24y6z
Verified for
  • Adobe
  • Atlassian
  • GlobalSign
  • Google
  • Meta
  • Microsoft
  • Microsoft 365
  • Workplace

Email authentication strong

SPF
v=spf1 include:spf.protection.outlook.com include:_spf.general.transactional-mail-a.com include:spf.messagelabs.com include:spf.sps-ocs.co.uk ip4:157.96.80.49 ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; rua=mailto:mvb73pgw@ag.eu.dmarcian.com;
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApEERWp7z/9BXx5Yi+g/k8ig6un5whxPckiD+V5whuRamQmPV8YL2NewDj1SqmcE0JGV1Nvt0Qu5GUV…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAriqc/Im6ps/3QGxw0FoHgh5Vi0jqs00qcpA42cICjm6vXErFx/AH3iO+BAI87MkO+fkAPigihSK/Kqq/Ir…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs4C3jeeLVaUQKvudmVy8XHoWoRIXdWHNzFJScl5na2aSMWapgj0R2EH7TG4SxQUt9XIRmR9ldNyiCZyyPP…
selectors probed

Certificate (current)

Sectigo Public Server Authentication CA DV R36
from 2026-05-06 to 2026-11-21
Expires in 184 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.jewson.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
geolocation=(self "https://www.google.com" "https://maps.googleapis.com"), camera=(self), microphone=(self)
x-content-type-options
nosniff
content-security-policy
script-src 'self' *.adsrvr.org *.adnxs.com *.omtrdc.net *.oktacdn.com *.jewson.co.uk *.adobedtm.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleapis.com *.gstatic.com *.bing.com *.facebook.net *.youtube.com *.ytimg.com *.civiccomputing.com *.hotjar.com *.jewson-beta.co.uk *.licdn.com *.googleadservices.com *.g.doubleclick.net *.frazersolutions.co.uk *.jewsonpartnershipsolutions.com *.partsarena.com *.twitter.com *.ads-twitter.com *.brsrvr.com *.smg.com https://*.decibelinsight.net https://*.decibelinsight.com 'unsafe-inline' 'unsafe-eval' blob: *.rakuten.com applepay.cdn-apple.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.marinsm.com *.increasingly.co *.increasingly.com;;img-src * data: smct.co *.smct.co smct.io *.smct.io *.marinsm.com *.amazonaws.com;;default-src 'self' *.oktacdn.com *.jewson.co.uk *.typekit.net *.google.com *.googleapis.com *.gstatic.com *.google-analytics.com 'unsafe-inline' *.increasingly.co *.increasingly.com;frame-src 'self' *.d
strict-transport-security
max-age=31536000; includeSubDomains

Links to (4)

Linked from (4)