pennyappeal.org
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- cdnjs.cloudflare.com×7
- cdn.jsdelivr.net×6
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- Penny Appeal Campus FREEPOST Thornes Park Wakefield WF2 8QZ
Registration
- Registrar
- IONOS SE
- Created
- 2005-11-08
- Expires
- 2028-11-08 903 days left
- Updated
- 2024-04-06
- Name servers
-
- ed.ns.cloudflare.com
- paityn.ns.cloudflare.com
DNS records live
- NS
-
- ed.ns.cloudflare.com
- paityn.ns.cloudflare.com
- MX
-
- 0 pennyappeal-org.mail.protection.outlook.com
- TXT
-
Show 11 TXT records
access-domain-verification=e64cdf632a93e224daf89fd53e3eafc42926a40847ad0aec636a6d0cada3ebb6apple-domain-verification=xQ21n4PLtgzFOWLLasv=111722c949ccbecb1eb27e54bb1a4db3atlassian-domain-verification=tI5QvzG4Rh7bfeWLaM4apHnllJBsgxHPC27/IVGLA7VUq/EGh4afmt/GF1FCZYi4dj5jdtls9mg8b26gd58qrzx9c5qm9jwfgoogle-site-verification=K-D5fm7jOXA8evMRkfUjxD_vNimLHyi1pnd-6kbRLqYgoogle-site-verification=THVRP-9Il3Uo57a9ebYHFuzonC_kvOXL3_zaZxzVSD4intacct-esk=4911588709F6CF44E0638D06450A9EC4xsy8zzg8m1h1rjsb38yp33dd22nbjq9y1hdcxmysh8gcbvfkn58k3w85pptl29z0_77qxjru8j3xc8j7u8sk02kmnjf6rod2
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net include:spf.uk.emailsignatures365.com include:mailcontrol.com include:out.accesspaysuite.com include:_spf.salesforce.com include:fsspfeuc.freshemail.io include:_spf.intacct.com ip4:80.193.244.231 ip4:80.193.244.226 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantinepolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDihCKHoztZjM9YLPsAxhsO7NkrhLU7WkeabXTUuU+IlP1t34mt1aJjm/GxoQTFyfO1qMS1ypXNxCDrR7djQd… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - selector1:
Certificate (current)
WE1
Expires in 25 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-eval' 'unsafe-inline' https://connect.facebook.net https://kit.fontawesome.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://tgbwidget.com https://payments.worldpay.com https://platform.twitter.com https://cdn.worldpay.com https://www.paypal.com https://www.paypalobjects.com https://www.gstatic.com https://www.google.com https://www.google-analytics.com https://optimize.google.com https://tagmanager.google.com https://www.googletagmanager.com https://ssl.google-analytics.com/ https://connect.facebook.net/ https://www.googleoptimize.com/ https://www.googleadservices.com/ https://connect.facebook.net https://www.mytennights.com https://zakatcalculator.co.uk https://*.hotjar.com https://bat.bing.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.usemessages.com https://js.hs-analytics.net https://js.hs-banner.com https://googleads.g.doubleclick.net https://mytendays.com/ https://*.quantserve.com https://*.quantcount.com https://*.- strict-transport-security
max-age=31536000; preload