payplanplus.com

.com crawl

First seen 2026-04-21 · Last seen 2026-05-15 · ok HTTP/1.1 200 1350 ms crawled 2026-05-15

GB · 18.130.28.249 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
PayPlan Plus
Description
PayPlan Plus helps you manage your free PayPlan debt solution online and deal with creditors. Great budgeting tools and help to reduce your bills.
Language
en

Technology

Server
Apache
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.googleapis.com×1
  • www.google.com×1
  • www.googletagmanager.com×1

Registration

Registrar
CSC Corporate Domains, Inc.
Created
2010-10-01
Expires
2026-10-01 133 days left
Updated
2025-09-27
Name servers
  • ns0.ukfast.net
  • ns1.ukfast.net

DNS records live

NS
  • ns0.ukfast.net
  • ns1.ukfast.net
MX
  • 10 d235249.a.ess.uk.barracudanetworks.com
  • 10 d235249.b.ess.uk.barracudanetworks.com
Verified for
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:spf.totemic.co.uk include:servers.mcsv.net -all
strict (-all)
DMARC
v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_agg@vali.email,mailto:rua+payplanplus.com@dmarc.barracudanetworks.com; ruf=mailto:ruf+payplanplus.com@dmarc.barracudanetworks.com
policy: reject (enforced)
DKIM
  • selector1: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsiCOQFyC1AvY5ZoQSZyuCC70pYlPrpUf1tDsvnib9MFyWO3neWwwjryZJ3XnyadxZKJHm8bvsOQTJg…
  • k1: k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo…
selectors probed

Certificate (current)

E7
from 2026-04-27 to 2026-07-26
Expires in 67 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.payplanplus.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
img-src * 'self' data: https:; style-src * 'self' 'unsafe-inline', default-src 'self' https://*.securetrading.net https://www.google.co.uk https://*.facebook.net http://*.facebook.net http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://script.hotjar.com https://static.hotjar.com https://connect.facebook.net https://browser-update.org https://www.googletagmanager.com https://apis.google.com https://www.google-analytics.com www.google-analytics.com https://stats.g.doubleclick.net https://ssl.google-analytics.com www.google.com www.gstatic.com https://api-iam.eu.intercom.io https://widget.intercom.io https://js.intercomcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' https://www.payplan.com https://stats.g.doubleclick.net http://stats.g.doubleclick.net https://www.fa
strict-transport-security
max-age=63072000; includeSubdomains;

Linked from (1)