lotterygoodcauses.org.uk
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Analytics
-
- Google Tag Manager
- Ads
-
- Meta Pixel
- Social widgets
-
- Twitter Widget
Third-party hosts loaded (5)
- connect.facebook.net×1
- platform.twitter.com×1
- unpkg.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- Tucows Inc t/a Tucows
- Created
- 1999-11-26
- Expires
- 2026-11-26 189 days left
- Updated
- 2025-10-28
- Name servers
-
- dns0.star.co.uk.
- dns1.star.co.uk.
DNS records live
- NS
-
- dns0.star.co.uk
- dns1.star.co.uk
- MX
-
- 0 lotterygoodcauses-org-uk.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 ip4:213.219.55.25 ip4:167.89.48.130 ip4:31.221.8.228 ip4:31.221.8.245 ip4:31.221.9.4 ip4:62.73.165.137 include:servers.mcsv.net include:mailcontrol.com include:sendgrid.net include:spf.exclaimer.net include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:ZohaUzK3BBa@dmarc-rua.mailcheck.service.ncsc.gov.uk; ruf=mailto:DMARC_Failures@lotterygoodcauses.org.uk; fo=1; pct=100; ri=3600policy: reject (enforced) - DKIM
-
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQvagFqXB1odtHucfNx+IzoA7nFloP02srxN3VkzLdeq0N3ZFfh8xqdSm5ohk2K9+vFcGRZvDCtd6RGo534P… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoAVO6Ux4I/Ic0nBnpV7gAZ70LkHKXNTjgtq/RW4olVsnn3n6RSZqQIyze8IcsNf4T96fbo16slB1X0NtkP… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxeNI6N5nqfW+p6ldo5QN6YQ1Kss54nBp2AD0+7WcQ/tsw47fj5fdixT/olsN4ZA+lGx0fTqyhJ1zOyXEiiv1mD8…
selectors probed - selector2:
Certificate (current)
E8
Expires in 77 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src * https: data: blob: android-webview-video-poster: 'unsafe-inline' 'unsafe-eval'; object-src 'none'; frame-ancestors 'self';- strict-transport-security
max-age=31536000; includeSubDomains