ppfmembers.org.uk

.uk crawl

First seen 2026-04-30 · Last seen 2026-05-19 · ok HTTP/1.1 200 6223 ms crawled 2026-05-08

US · 104.18.1.25 · AS13335 Cloudflare, Inc.

Reputation 100/100

sector finance type homepage

HTML metadata

Title
Welcome to the Pension Protection Fund (PPF) Members Website
Description
Website used by the Pension Protection Fund (PPF) members to register or login for online services to manage their pensions.
Language
en

Technology

CDN
Cloudflare
CMS
Joomla

Third-party hosts loaded (1)

  • www.google.com×1

Social

Registration

Registrar
123-Reg Limited t/a 123-reg
Created
2014-07-02
Expires
2027-07-02 407 days left
Updated
2025-07-03
Name servers
  • lynn.ns.cloudflare.com.
  • sofia.ns.cloudflare.com.

DNS records live

NS
  • lynn.ns.cloudflare.com
  • sofia.ns.cloudflare.com
MX
  • 30 eu-smtp-inbound-1.mimecast.com
  • 30 eu-smtp-inbound-2.mimecast.com
TXT
  • hwn7p9zp8gkzxj60s7dgnbfrbpdsgs1w

Email authentication strong

SPF
v=spf1 include:eu._netblocks.mimecast.com include:spf-uk.emailsignatures365.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:dmarc-rua@ppf.co.uk,mailto:YTdWoZNKKPh@dmarc-rua.mailcheck.service.ncsc.gov.uk; ruf=mailto:dmarc-ruf@ppf.co.uk; fo=1; sp=reject;
policy: reject (enforced) · sp=reject
DKIM
no key found at common selectors

Certificate (current)

DigiCert EV RSA CA G2
from 2025-07-04 to 2026-08-05
Expires in 76 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://www.ppfmembers.org.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; script-src-elem 'self' data: 'unsafe-inline' https://*.ppfmembers.org.uk/ https://statse.webtrendslive.com https://www.promisejs.org https://www.googletagmanager.com https://www.gstatic.com https://www.google.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; img-src 'self' https://i.ytimg.com blob: data: https://statse.webtrendslive.com; font-src 'self'; connect-src 'self' https://region1.google-analytics.com; frame-src 'self' https://www.research.net/ https://www.youtube.com https://www.google.com; frame-ancestors 'self'; form-action 'self'
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (7)

Linked from (2)