macbrookgas.co.uk
HTML metadata
Technology
- Server
Registration
- Registrar
- Namecheap, Inc.
- Created
- 2017-03-14
- Expires
- 2027-03-14 297 days left
- Updated
- 2026-02-15
- Name servers
-
- dns1.registrar-servers.com.
- dns2.registrar-servers.com.
DNS records live
- NS
-
- dns1.registrar-servers.com
- dns2.registrar-servers.com
- MX
-
- 0 macbrookgas-co-uk.mail.protection.outlook.com
- TXT
-
v=spf1 a mx include:_spf.elasticemail.com include:emailsrvr.com include:spf.protection.outlook.com include:spf.bigchange.com ~allreplit-verify=84889819-300c-467d-ba01-ad6b222fc184
- Verified for
-
- Microsoft 365
Certificate (current)
E7
Expires in 29 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'nonce-HzoSZJgjje7wnAVwGfwS8w==' 'strict-dynamic' https://www.googletagmanager.com https://www.google-analytics.com https://js.stripe.com https://finance.blackhorseflexpay.co.uk; script-src-attr 'none'; style-src 'self' 'nonce-HzoSZJgjje7wnAVwGfwS8w=='; style-src-attr 'unsafe-inline'; font-src 'self'; img-src 'self' data: https: blob:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://region1.google-analytics.com https://api.stripe.com https://api.gocardless.com https://*.blackhorseflexpay.co.uk https://*.blackhorse.co.uk wss: ws:; frame-src 'self' https://js.stripe.com https://www.youtube.com https://youtube.com https://finance.blackhorseflexpay.co.uk; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests- strict-transport-security
max-age=63072000; includeSubDomains- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-resource-policy
same-site