norifinancial.co.uk
HTML metadata
Technology
Third-party hosts loaded (2)
- partnership-assets.sjp.co.uk×4
- cloud.comms.sjpp.co.uk×1
Social
Contact
- Address
- Suite 14, The Beehive Lion's Drive, BB1 2QS, Blackburn
DNS records live
- NS
-
- ns-1328.awsdns-38.org
- ns-1783.awsdns-30.co.uk
- ns-319.awsdns-39.com
- ns-691.awsdns-22.net
- MX
-
- 10
Email authentication strong
- SPF
-
v=spf1 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; adkim=s; aspf=spolicy: reject (enforced) · sp=reject - DKIM
-
Show 12 DKIM selectors
- default:
v=DKIM1; p= - google:
v=DKIM1; p= - selector1:
v=DKIM1; p= - selector2:
v=DKIM1; p= - k1:
v=DKIM1; p= - k2:
v=DKIM1; p= - mail:
v=DKIM1; p= - dkim:
v=DKIM1; p= - s1:
v=DKIM1; p= - s2:
v=DKIM1; p= - mxvault:
v=DKIM1; p= - smtpapi:
v=DKIM1; p=
selectors probed - default:
Certificate (current)
R12
Expires in 36 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
accelerometer=(),ambient-light-sensor=(),attribution-reporting=(),battery=(),camera=(),conversion-measurement=(),cross-origin-isolated=(),direct-sockets=(),display-capture=(),document-domain=(),encrypted-media=(),execution-while-not-rendered=(),execution-while-out-of-viewport=(),focus-without-user-activation=(),gamepad=(),geolocation=(),gyroscope=(),hid=(),idle-detection=(),interest-cohort=(),magnetometer=(),microphone=(),midi=(),navigation-override=(),otp-credentials=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),shared-autofill=(),speaker-selection=(),storage-access-api=(),sync-script=(),sync-xhr=(),trust-token-redemption=(),usb=(),vertical-scroll=(),wake-lock=(),web-share=(),window-placement=(),xr-spatial-tracking=(),bluetooth=(), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-prefers-color-scheme=(), ch-prefers-reduced-motion=(), ch-rtt=(), ch-save-data=(), ch-ua=(), ch-ua-arch=(), ch-ua-bitness=(), ch-ua-full-version=(), ch-ua-full-version-- x-content-type-options
nosniff- content-security-policy
connect-src 'self' *.uk.deptagency.com *.sjp-cloud.info *.gstatic.com *.sjp.co.uk localhost:* www.googleadservices.com *.google.com *.google.co.uk *.googletagmanager.com pagead2.googlesyndication.com *.googleapis.com *.google-analytics.com *.analytics.google.com analytics.google.com *.doubleclick.net recaptcha.net *.recaptcha.net *.vouchedfor.co.uk api.edq.com *.trustarc.com *.zscloud.net *.linkedin.oribi.io *.linkedin.com *.facebook.com sjp.bynder.com *.shorthand.com *.shorthandstories.com;default-src 'self' *.uk.deptagency.com *.sjp-cloud.info *.sjp.co.uk localhost:* *.getmediamanager.com *.gstatic.com *.google.com *.google.co.uk recaptcha.net *.youtube.com *.zscloud.net *.linkedin.oribi.io *.linkedin.com *.facebook.com sjp.bynder.com *.shorthandstories.com *.shorthand.com;font-src partnership-assets.sjp.co.uk theinvestor.shorthandstories.com consent.trustarc.com fonts.gstatic.com fonts.idigitalcontents.com;frame-src 'self' *.uk.deptagency.com *.sjp-cloud.info bid.g.doubleclick.net t- strict-transport-security
max-age=31536000; includeSubDomains; preload, max-age=63072000