postcodeculturetrust.org.uk
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (2)
- cdn-ukwest.onetrust.com×2
- www.googletagmanager.com×1
Contact
- Address
- st is a registered Scottish charity (SC04323
DNS records live
- NS
-
- ns-1097.awsdns-09.org
- ns-138.awsdns-17.com
- ns-1817.awsdns-35.co.uk
- ns-627.awsdns-14.net
- MX
-
- 10 mxa-002f0501.gslb.pphosted.com
- 10 mxb-002f0501.gslb.pphosted.com
- TXT
-
MS=ms42945072kJyJDS69CHuoDM3wnzvEtYqJM0n5r+MhTdTLWsZCvYIkR4OsFsOvM+AhkO/h1VhnpZpkMICYgF8CMVAHEWfYlA==
Email authentication strong
- SPF
-
v=spf1 include:spf-002f0501.pphosted.com include:_spf.salesforce.com include:spf1.formassembly.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; fo=1:d:s; rua=mailto:dmarc@up-lit.uriports.com; ruf=mailto:dmarc@up-lit.uriports.compolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 64 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(self), ambient-light-sensor=(self), autoplay=(self), battery=(self), camera=(self), clipboard-read=(self), clipboard-write=(self), conversion-measurement=(self), cross-origin-isolated=(self), display-capture=(self), document-domain=(self), encrypted-media=(self), execution-while-not-rendered=(self), execution-while-out-of-viewport=(self), focus-without-user-activation=(self), fullscreen=(self), gamepad=(self), geolocation=(self), gyroscope=(self), hid=(self), idle-detection=(self), interest-cohort=(self), keyboard-map=(self), magnetometer=(self), microphone=(self), midi=(self), navigation-override=(self), payment=(self), picture-in-picture=*, publickey-credentials-get=(self), screen-wake-lock=(self), serial=(self), speaker-selection=(self), sync-script=(self), sync-xhr=(self), trust-token-redemption=(self), usb=(self), vertical-scroll=*, web-share=(self), window-placement=(self), xr-spatial-tracking=(self),- x-content-type-options
nosniff- content-security-policy
connect-src 'self' ws: *.googletagmanager.com *.gstatic.com *.googleapis.com *.google-analytics.com *.googleanalytics.com *.youtube.com *.vimeo.com *.vimeocdn.com *.onetrust.com *.cookielaw.org *.cookiepro.com *.marker.io *.amazonaws.com *.umbraco.com *.userway.org snap.licdn.com *.linkedin.com sjs.bizographics.com; default-src 'self'; font-src 'self' *.googletagmanager.com *.gstatic.com *.googleapis.com *.google-analytics.com *.googleanalytics.com *.youtube.com *.vimeo.com *.vimeocdn.com *.onetrust.com *.cookielaw.org *.cookiepro.com *.marker.io *.umbraco.com *.userway.org snap.licdn.com *.linkedin.com sjs.bizographics.com; form-action 'self' *.onetrust.com *.userway.org *.youtube.com *.postcodecommunitytrust.org.uk *.staging.postcodecommunitytrust.org.uk *.ppl-community-trust.lewiscc.dev *.ppl-earth-trust.lewiscc.dev *.ppl-dream-fund.lewiscc.dev; frame-ancestors 'self'; frame-src 'self' *.googletagmanager.com *.gstatic.com *.googleapis.com *.google-analytics.com *.googleanalytics.co- strict-transport-security
max-age=31536000; includeSubDomains