lesormesjersey.co.uk
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (8)
- campmap.com×3
- fonts.bunny.net×2
- www.googletagmanager.com×2
- banner.cookiescan.com×1
- d3e85ikkjrhqme.cloudfront.net×1
- fonts.gstatic.com×1
- js.createsend1.com×1
- player.vimeo.com×1
Contact
- Address
- Mont a la Brune, JE3 8FL, St Brelade, Jersey
DNS records live
- NS
-
- ns1.bdm.microsoftonline.com
- ns2.bdm.microsoftonline.com
- ns3.bdm.microsoftonline.com
- ns4.bdm.microsoftonline.com
- MX
-
- 0 lesormesjersey-co-uk.mail.protection.outlook.com
- TXT
-
mscid=kZBgqdm4zHy8pl2HkIQTf9rfrEoyzu9twMOaZ9Pd4LizOlOaZKejiWXB/TcMEZy7NTs2ambwuezskU4LBDD7Tw==
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:_spf.createsend.com include:amazonses.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7GMvt4lVgjhbQSJyO514DXkZtWCoUJqRXcyznDVLAJbx4SQN+ZUK/kMt7NClaNoJVttzUm3R/1nab1w/8XA…
selectors probed - selector1:
Certificate (current)
R12
Expires in 74 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src https: data: 'self'; frame-src *; object-src 'self'; script-src 'self' 'unsafe-eval' *.google-analytics.com *.googletagmanager.com *.fonts.net *.createsend1.com google.com *.google.com gstatic.com *.gstatic.com cdn.3cx.com *.paypal.com js.braintreegateway.com assets.braintreegateway.com *.cardinalcommerce.com songbird.cardinalcommerce.com https://try.access.worldpay.com https://access.worldpay.com *.worldpay.com https://loader.wisepops.com https://wisepops.net *.facebook.net https://googleads.g.doubleclick.net *.bing.com *.cookiescan.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://cdn.wisepops.com 'nonce-ff2a7f0f627d48538f1c1e5a28588749'; img-src 'self' data: https: *.google-analytics.com google-analytics.com google-analytics.com *.umbraco.org gravatar.com *.gravatar.com gstatic.com *.gstatic.com i1.wp.com assets.braintreegateway.com; style-src 'self' 'unsafe-inline' *.fonts.net *.cloudfront.net *.typekit.net assets.braintreegateway.com https://f- strict-transport-security
max-age=31536000