moneyway.co.uk

.uk crawl

First seen 2026-05-04 · Last seen 2026-05-29 · ok HTTP/1.1 200 1247 ms crawled 2026-05-29

US · 107.154.214.46 · AS19551 Incapsula Inc

Reputation 100/100

sector finance type homepage

HTML metadata

Title
Moneyway
Description
Moneyway are established as a trusted lender in the broker and dealer market. We offer finance solutions for dealers and brokers.
Language
en-gb
Canonical
https://www.moneyway.co.uk

Technology

Server
Apache
CMS
Joomla
Analytics
  • Google Tag Manager

Third-party hosts loaded (2)

  • static.srcspot.com×1
  • www.googletagmanager.com×1

Registration

Registrar
GoDaddy.com, LLC.
Created
2007-01-17
Expires
2028-01-17 595 days left
Updated
2025-01-14
Name servers
  • ns1-06.azure-dns.com.
  • ns2-06.azure-dns.net.
  • ns3-06.azure-dns.org.
  • ns4-06.azure-dns.info.

DNS records live

NS
  • ns1-06.azure-dns.com
  • ns2-06.azure-dns.net
  • ns3-06.azure-dns.org
  • ns4-06.azure-dns.info
MX
  • 10 eu-smtp-inbound-2.mimecast.com
  • 5 eu-smtp-inbound-1.mimecast.com
TXT
Show 4 TXT records
  • sending_domain675063=9918e216b34606de6780f40f11e88451745a084f978bea5979e54113e342a7b7
  • xvzrjlz8w8qq8q27p0xl4pm7lxjg8j1r
  • _hmy2ypr9nmnh3i23uw8danwbh27nvd6
  • TQ2/vOJwbfmFGtP1jk9p2v57hAb+hZEbubr+6PCc5eNBSN+ywWump+o0p812lSrtAa0zA54xkKMtUnENX4mOKg==
Verified for
  • GlobalSign
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:aspmx.pardot.com include:_netblocks.mimecast.com ~all
softfail (~all)
DMARC
v=DMARC1; p=reject; rua=mailto:0d367b365617482@rep.dmarcanalyzer.com; ruf=mailto:0d367b365617482@for.dmarcanalyzer.com; adkim=s; aspf=s; fo=1;
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

Thawte TLS RSA CA G1
from 2026-01-12 to 2027-02-13
Expires in 257 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.moneyway.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • referrer-policy
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing content type protection
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
content-security-policy
default-src 'self' https://*.securetrustbank.com https://*.moneyway.co.uk https://*.googletagmanager.com;; connect-src 'self' https://*.google-analytics.com https://cdn.cookielaw.org https://*.feefo.com https://*.trustpilot.com https://*.civiccomputing.com;; img-src 'self' data: https://*.googletagmanager.com https://*.google-analytics.com https://*.google.com https://*.google.co.uk https://siteimproveanalytics.com https://*.v12vf.co.uk https://*.global.siteimproveanalytics.io https://*.feefo.com;; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.securetrustbank.com https://*.moneyway.co.uk https://*.googletagmanager.com https://cdn.cookielaw.org https://*.google-analytics.com https://siteimproveanalytics.com https://*.feefo.com https://*.trustpilot.com https://static.srcspot.com https://code.jquery.com;; style-src 'self' 'unsafe-inline' https://*.securetrustbank.com https://*.moneyway.co.uk https://*.feefo.com;; font-src 'self' https://*.securetrustbank.com https://*.moneywa
strict-transport-security
max-age=31536000; includeSubDomains; preload
cross-origin-opener-policy
same-origin

Links to (2)

Linked from (2)