principalinsurance.co.uk
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- nginx
Third-party hosts loaded (1)
- static.mbshosting.co.uk×224
Contact
- Phone
DNS records live
- NS
-
- ns1.livedns.co.uk
- ns2.livedns.co.uk
- ns3.livedns.co.uk
- MX
-
- 10 principalinsurance-co-uk.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
e7vpi0h4cvhoslio2qp0m8prbj202306010820273q5re6wvg0ypo45nzlsomkz0nkz1wsvf5qt5ufl571kglof2ucNP4jL9gIldCHdHB6JqAAbDZBcB+qekKOscCzsWXlgl3JwFXHTajCGlXvwxiC2DeI9SyYoZOezMT9m0lRtGtRtw==3edc5tb5q3e2a96s7up35c9bcqvvtu58ppjsc54k1eq1n08dkb4tmlh6kck7mkjnms8361i8f9a40a
- Verified for
-
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:91.198.99.0/24 include:mail.opengihosting.co.uk Include:mail1.opengihosting.co.uk include:sendgrid.insly.com include:sendgrid.net ip4:217.20.43.92 ip4:46.23.230.0/24 -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:mailalerts@principalinsurance.co.uk; ruf=mailto:mailalerts@principalinsurance.co.uk; fo=1policy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8A2TzTbytoCsf11ktrYTevfhhbnCXkHNg7OfzLeexRhpAClUoD7Iz55HgHGX4we+ZhxiJQVLHi9jJ2GdHqG… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv3KaaYi1vGvxSbrbZrT1xh2oVz3izYXdLrp6IjYuGLQ68VG8SykWjEOSIQwMU9BNv2W9mgVk/s5eg4VhUa… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCn/QaULgHTJMdf+kfGYIB5yBrarVlhYzfl0wA4z+a0myAt0uZd0qQPnsHc8jdZRMwXQKnrDR/w2jSgtbhb3JVPFj…
selectors probed - selector1:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 134 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
base-uri 'self';font-src 'self' fonts.gstatic.com;object-src 'none';script-src 'self' 'strict-dynamic' 'nonce-JYgOLAPn7romGRUJm6TprpjMAgaESGt9';style-src 'self' 'unsafe-inline' app.five9.eu fonts.googleapis.com- strict-transport-security
max-age=31536000; includeSubDomains