necat.co.uk
HTML metadata
Technology
- CMS
- Joomla
- Social widgets
-
- Twitter Widget
Third-party hosts loaded (2)
- js.stripe.com×1
- platform.twitter.com×1
Social
Contact
Registration
- Registrar
- Fasthosts Internet Ltd
- Created
- 2015-01-14
- Expires
- 2027-01-14 239 days left
- Updated
- 2024-12-15
- Name servers
-
- ns10.dnsmadeeasy.com.
- ns11.dnsmadeeasy.com.
- ns12.dnsmadeeasy.com.
- ns13.dnsmadeeasy.com.
- ns14.dnsmadeeasy.com.
- ns15.dnsmadeeasy.com.
DNS records live
- NS
-
- ns10.dnsmadeeasy.com
- ns11.dnsmadeeasy.com
- ns12.dnsmadeeasy.com
- ns13.dnsmadeeasy.com
- ns14.dnsmadeeasy.com
- ns15.dnsmadeeasy.com
- MX
-
- 10 mx01.qboxmail.com
- 20 mx02.qboxmail.com
Email authentication weak
- SPF
-
v=spf1 mx a:smtpweb.uk.endis.com include:spf.qboxmail.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 72 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
geolocation=(*),midi=(),sync-xhr=(*),microphone=(),camera=(*),magnetometer=(*),gyroscope=(*),fullscreen=(*),payment=(*)- x-content-type-options
nosniff- content-security-policy
default-src https: wss:; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; img-src https: data:; media-src https: blob:; worker-src https: blob:; frame-ancestors https:; form-action 'self' https:;- strict-transport-security
max-age=31536000; includeSubDomains