nutrapreps.co.uk
HTML metadata
Technology
- Server
- Microsoft-IIS
- CMS
- Next.js
Social
Registration
- Registrar
- Netcetera Ltd t/a Netcetera
- Created
- 2021-04-05
- Expires
- 2027-04-05 320 days left
- Updated
- 2026-04-01
- Name servers
-
- ns2304.nameservers.co.uk.
- ns2305.nameservers.co.uk.
DNS records live
- NS
-
- ns2304.nameservers.co.uk
- ns2305.nameservers.co.uk
- MX
-
- 10 mail.nutrapreps.co.uk
- TXT
-
zeroThreat=NDkxMQ==TkRreE1RPT0=TkRreE1RPT
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a mx ip4:82.25.22.38 a:cp2447.netcetera.co.uk ?allneutral (?all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email;policy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; h=sha256; k=rsa; s=email; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDHu95NKhuwFNriHi3a75ykHMswoQ8us95dt+YfdXNAVJoGSKM815yEODDaXFKV1np… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAol0LJCUBZyCavRHjBT3v9/P/9fkSDujX4DEU/yzoQbZS22DyS0LILxkQe3xMOQ+5hv04K9jbOo8zraLRrt… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAy09iVIsvXvmz6E7eH8dKOadyumqnegR0omTUDHAimgN8JosdXEEjjdw25hDnA0hFP5bF2DtQpUvBj/tcxm…
selectors probed - default:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 87 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; default-src 'self'; script-src 'self' 'nonce-ODU4ZTYxN2QtOTIzZi00NmRlLWJhYjYtODA3NjNlYTI1ODQx' 'strict-dynamic' 'unsafe-eval' https://checkout.stripe.com; style-src 'self' https://nutrapreps.b-cdn.net 'unsafe-inline'; img-src 'self' https://*.stripe.com https://nutrapreps.b-cdn.net https://images.unsplash.com https://placehold.co; connect-src 'self' https://checkout.stripe.com https://ukwest-0.in.applicationinsights.azure.com https://js.monitor.azure.com; frame-src 'self' https://checkout.stripe.com; font-src 'self' data:; media-src 'self' https://nutrapreps.b-cdn.net; object-src 'none'; base-uri 'self'; form-action 'self';- strict-transport-security
max-age=63072000; includeSubDomains; preload