kff.co.uk
HTML metadata
Technology
- Server
- Apache
- Stack
- Laravel
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (4)
- www.googletagmanager.com×2
- cdn.cookielaw.org×1
- cdn.evgnet.com×1
- www.google.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- udns1.cscdns.net
- udns2.cscdns.uk
- MX
-
- 10 mx0a-00133a01.pphosted.com
- 10 mx0b-00133a01.pphosted.com
- TXT
-
_23mjcqcut6la3ycd98f2t7fup8krqdg_9renxwctzca01i44f1ojrl2oa64n57a_roouhe4j5foq0db3ufr6613mv5sr4p7
- Verified for
-
- Apple
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 ip4:185.151.31.85 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.compolicy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 216 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
fullscreen=(self); geolocation=(self);- x-content-type-options
nosniff- content-security-policy
upgrade-insecure-requests; report-uri /cspreport; default-src 'self' https://cdn.evergage.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://use.typekit.net https://connect.facebook.net https://global.oktacdn.com https://*.cookielaw.org https://www.google-analytics.com *.googleapis.com https://www.gstatic.com https://www.google.com https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' https://*.evgnet.com https://*.evergage.com https://*.cloudfront.net https://online.flippingbook.com https://*.qualtrics.com https://cdn.evgnet.com https://*.hotjar.com https://connect.facebook.net https://cdn.cookielaw.org http://ajax.googleapis.com https://global.oktacdn.com https://www.gstatic.com https://www.google.com https://player.vimeo.com https://www.googletagmanager.com https://www.google-analytics.com https://www.sysco.com; style-src 'self' 'unsafe-inline' https://global.oktacdn.com; style-src-elem 'self' 'unsafe-inline' https://*.evgnet.com https://*.evergage- strict-transport-security
max-age=31536000
Links to (5)
- sysco.com×1
- linkedin.com×1
- kffcareers.uk×1
- instagram.com×1
- 360ss.com×1