patientsafetycongress.co.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Fonts
-
- Font Awesome
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (6)
- cdn.jsdelivr.net×4
- cdnjs.cloudflare.com×3
- go.hsjinformation.co.uk×1
- use.fontawesome.com×1
- www.googletagmanager.com×1
- www.youtube.com×1
Social
DNS records live
- NS
-
- ns1.lexsynergy.net
- ns2.lexsynergy.us
- ns3.lexsynergy.info
- MX
-
- 0 eu-smtp-inbound-1.mimecast.com
- 0 eu-smtp-inbound-2.mimecast.com
- TXT
-
ssjplv9k90wlqyk0623jgxt6m056h4ct0ed1fe018abf8f15d9c2964e038dd1c8866404adf50ed1fe018af3f33d0684084c7f833427638d23f276
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 ip4:192.0.2.0/24 ip4:198.51.100.123 mx include:_netblocks.mimecast.com ip4:213.131.182.34 include:msgfocus.com include:salesforce.com include:spf.protection.outlook.com include:mktomail.com Include:mail.zendesk.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 44 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://*.fontawesome.com/ https://*.googletagmanager.com/ https://*.cloudflare.com/ https://*.jsdelivr.net/ https://*.google-analytics.com/ https://*.licdn.com/ https://cookie-script.com/ https://*.cookie-script.com/ https://*.facebook.net/ https://*.marketo.net/ https://*.doubleclick.net/ https://*.hsjinformation.co.uk/ https://*.swapcard.com/ https://*.stripe.com/v3/ https://*.fontawesome.com/ https://www.googletagmanager.com/ https://*.cookie-script.com:* https://*.intercom.com https://*.marketo.net https://*.twitter.com/ https://*.twitter.com/ https://*.onesignal.com https://*.tableau.com/; object-src 'none'; style-src 'self' 'unsafe-inline' https://*.jsdelivr.net https://*.cloudflare.com/ https://*.googleapis.com/ https://*.fontawesome.com/ https://www.googletagmanager.com/ https://*.jsdelivr.net/ https://*.hsjinformation.co.uk/ https://*.marketo.net; img-src 'self' data: https://*.linkedin.com/ http- strict-transport-security
max-age=31536000, max-age=300