nhg.org.uk
HTML metadata
Technology
Third-party hosts loaded (3)
- ajax.googleapis.com×1
- cc.cdn.civiccomputing.com×1
- unpkg.com×1
Social
Contact
- Phone
Registration
- Registrar
- 123-Reg Limited t/a 123-reg
- Created
- 2018-06-23
- Expires
- 2026-06-23 34 days left
- Updated
- 2025-06-24
- Name servers
-
- adaline.ns.cloudflare.com.
- will.ns.cloudflare.com.
DNS records live
- NS
-
- adaline.ns.cloudflare.com
- will.ns.cloudflare.com
- MX
-
- 0 nhg-org-uk.d-v1.mx.microsoft
- 10 nhg-org-uk.mail.protection.outlook.com
- TXT
-
Show 18 TXT records
globalsign-domain-verification=5X3H1NqVHFqwSENSt8xqqgN-JDX03tQXKSMd6Inb8d8rrj3w98cwy36wnr1jrcxsgyw76q81rjzXEdOKEeH7SwSn2M2FbOV3+EkfOsloKZp6/f90jIeSY=google-site-verification=se8hjMYa5ns4kX2ZMu9W_B0Mx6P21abH2OM37pMqr4Agoogle-site-verification=q-WzLca3o5Pe8hVAkS1I8yVteaKQwl5SBruJCVWiHeU_4tqpvugytx4cmxvo32tbcr1i7jdmkkl0ed1fe018a4d61fa1ba94b41e699281fb88ae7f5959dKaFAkCnmrKDK8q/w8yulxrh+ZNqYR3tTuL+lioLdM=d365mktkey=dx5RhMdnxovdlOzoFPiHmg5GAPKFX5quGxxJnfP9Z6Ex_globalsign-domain-verification=kWueFQgHhiIxYftUUhwgtJT_hbFawzHzV_y79zjHJFvz5tcc8fkfwhs2bv6mgkmsbjkhgrbb84p4vlk1pt1sdyvkvtw67q6yw1wznmqqbpMS=ms61232565MS4210409nfw19dx7mt1bh79csf00b7zprgfp4xjdocusign=56d0fad3-0211-4ca5-88a2-8483be672082+0GJQh506cQtVkvTzSO4JdUh8/GtxVmhPsT76xHFNXQ=d3738a73b4d64433b8c757abbf17d723
Email authentication strong
- SPF
-
v=spf1 ip4:167.89.19.59 ip4:20.108.146.184 ip4:20.58.112.52 ip4:208.185.229.0/24 ip4:18.168.51.200 ip4:18.168.140.58 ip4:13.79.245.74 ip4:148.59.101.16/28 include:spf.protection.outlook.com include:servers.mcsv.net include:_spf.psm.knowbe4.com include:_spf.elasticemail.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:68b85b63aadd2@ag.dmarcly.com; ruf=mailto:68b85b63aadd2@fo.dmarcly.com; sp=quarantine; fo=0;policy: quarantine · sp=quarantine - DKIM
-
Show 5 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt1j+Q1Fvrq7EiCGVVxB+wvU2iru6TWCQZ2xUQ/IB9U6xRjcH0ksx+8JhBjIBgQLcniBw9SJ993j94O… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApazow84vHwY+91MK+XR9H8qQRS1YZbox3AbIvWmbob7KIwvGLqhWG5KPAwJRwxgYRrZRnJmLPTdSyZ… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvkHMvbXY8Bf+RQuoHmbnCD58yhyjBMLZG7x5Rdof2neK2Ax+En/SKW/f550+vQQHCd47jgR6ZOqV2/i4qU… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0vylgmedxj9YO7gKbCa3XRxjdJEyZn84uJ0AbKKCNB7bGQVsqi8R4yivw0/F+OA+yuwSEulmRYfd46g1NT…
selectors probed - selector1:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 92 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' packages.umbraco.org our.umbraco.org;script-src 'self' cdnjs.cloudflare.com code.jquery.com ajax.googleapis.com maps.google.com siteimproveanalytics.com www.googletagmanager.com *.gstatic.com www.google-analytics.com maps.googleapis.com www.youtube.com connect.facebook.net *.civiccomputing.com unpkg.com/@googlemaps/markerclusterer/dist/index.min.js use.typekit.net www.google.com Mailchimp.com www.mailchimp.com static.zdassets.com script.crazyegg.com www.facebook.com static.hotjar.com script.hotjar.com tags.srv.stackadapt.com nottinghillgenesis.zendesk.com ekr.zdassets.com v2.zopim.com s7.addthis.com widget-mediator.zopim.com qvdt3feo.com 'unsafe-eval' 'unsafe-inline';style-src 'self' fonts.googleapis.com cdn-images.mailchimp.com use.typekit.net p.typekit.net use.fontawesome.com Mailchimp.com www.mailchimp.com tags.srv.stackadapt.com 'unsafe-inline';connect-src 'self' maps.googleapis.com *.google-analytics.com *.google.com *.civiccomputing.com Mailchimp.com www.mailch- strict-transport-security
max-age=63072000; includeSubDomains; preload