preloved.co.uk

.uk crawl

First seen 2026-04-12 · Last seen 2026-05-30 · ok HTTP/1.1 200 2429 ms crawled 2026-05-20

GB · 31.177.17.35 · AS197651 Fic Shareco Limited

Reputation 100/100

Classifying

HTML metadata

Title
Preloved | Free Classified Ads | Buy and Sell Second Hand
Description
Buy and sell second hand items, and more, in your local area. List for free with Preloved classified ads, in over 500 categories!
Language
en

Technology

Server
nginx
CMS
Gatsby
Analytics
  • Google Tag Manager
Cookie consent
  • OneTrust
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • fonts.googleapis.com×2
  • cdn.cookielaw.org×1
  • fonts.gstatic.com×1
  • www.googletagmanager.com×1

Social

Registration

Registrar
Key-Systems GmbH
Created
1998-10-08
Expires
2027-10-08 494 days left
Updated
2024-09-24
Name servers
  • dns1.p05.nsone.net.
  • dns2.p05.nsone.net.
  • dns3.p05.nsone.net.
  • dns4.p05.nsone.net.
  • ns01.thg-ns.net.
  • ns02.thg-ns.net.
  • ns03.thg-ns.net.
  • ns04.thg-ns.net.

DNS records live

NS
  • dns1.p05.nsone.net
  • dns2.p05.nsone.net
  • dns3.p05.nsone.net
  • dns4.p05.nsone.net
  • ns01.thg-ns.net
  • ns02.thg-ns.net
  • ns03.thg-ns.net
  • ns04.thg-ns.net
MX
  • 25 eu-smtp-inbound-1.mimecast.com
  • 25 eu-smtp-inbound-2.mimecast.com
TXT
Show 6 TXT records
  • wz6qfmwqdrf33yw7r87p6hmpynpz1frw
  • pkh772j88dkdcdzn14d4qcxpcpz46s4p
  • gkmp5615b41rz1v4q39qw4b3l5nytwm5
  • fastly-domain-delegation-764852-2024514
  • 0ed1fe018a2e8ef0a0385a4196830d3013b32c7874
  • d903945979f945b2a0abe10b9d8cfe82
Verified for
  • Google
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:eu._netblocks.mimecast.com -all
strict (-all)
DMARC
v=DMARC1; p=reject; rua=mailto:aggregate@dmarc.thg.com; ruf=mailto:forensic@dmarc.thg.com; fo=1;
policy: reject (enforced)
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-03-10 to 2026-06-08
Expires in 8 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.preloved.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
script-src 'unsafe-inline' 'unsafe-eval' blob: *.preloved.co.uk *.thcdn.com *.cookielaw.org *.b-cdn.net *.affiliatefuture.com *.cloudfront.net *.sharethru.com *.media.net *.adventori.com *.amazon-adsystem.com onetag-sys.com *.omnitagjs.com *.zencdn.net *.2mdn.net *.33across.com *.openxcdn.net *.crwdcntrl.net *.sharethrough.com *.zenaps.com *.rokt.com *.googleadservices.com *.doubleverify.com *.doubleclick.net *.gstatic.com *.googlesyndication.com *.google-analytics.com *.google.com *.google.co.uk *.dwin1.com *.realvu.net *.contentsquare.net *.facebook.net *.googletagmanager.com *.googletagservices.com *.ampproject.org *.cheqzone.com *.roeyecdn.com *.cpx.to *.jquery.com *.twitter.com *.googleapis.com *.scorecardresearch.com *.hotjar.com *.amazonaws.com *.gatekeeperconsent.com *.ezojs.com *.ezodn.com *.ezoic.net *.quantserve.com *.quantcount.com *.pubmatic.com *.4dex.io *.criteo.net *.script.ac *.openx.net btloader.com *.privacymanager.io *.fastclick.net *.hadronid.net *.id5-sync.com *.a
strict-transport-security
max-age=63072000; includeSubDomains; preload

Links to (4)

Linked from (2)