property.nhs.uk
HTML metadata
Technology
- Server
- Microsoft-IIS
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (6)
- cdn.jsdelivr.net×1
- code.jquery.com×1
- consent.cookiebot.com×1
- extend.vimeocdn.com×1
- maps.googleapis.com×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns1.nhs.uk
- ns2.nhs.uk
- ns3.nhs.uk
- ns4.nhs.uk
- MX
-
- 0 property-nhs-uk.mail.protection.outlook.com
- TXT
-
Show 10 TXT records
ehkccefj82unu0jthvp96d8j2dk51kcf1qgm7hta9hj6d3r9tdud00D0O000000rwim=1TBPz00000001q14jxbx4810gkt4xgwtttz08mq0qjbd89580z31tz0c4nvbjncm8vfh1mmbb8zcy6tmsfpkey=2ddh8ie9uzgvoambv6h8r5wr1asv=4a34fd87fc7663208cd3320bf5fa61d4d365mktkey=3ou078doq1w1l11u6o7vi074jdomain.zoho.com.e10h33g5hd6nq2j422brs9ad6c
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:13.79.32.236 ip4:52.169.161.176 ip4:213.143.153.2 ip4:5.61.115.80/28 ip4:80.6.91.150 ip4:37.244.88.0/24 ip4:85.133.123.0/24 include:mailgun.org ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-rua@dmarc.service.gov.uk,mailto:cybersecurity@property.nhs.uk,mailto:dmarc_agg@vali.email; ruf=mailto:cybersecurity@property.nhs.ukpolicy: quarantine - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApjqN7G2GVNk812/A0mrxYK9Q2mYu9iST5LmecjBZg7TgK12a1Bh/GZSDzn6tYjGfpET8lP4cFuouLv… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAo37MX5DPpBaGpPrx3nt31VdIPZ40XsLiAzAQ2Tirb0osshzAulINHsli3a5d8yZKriUIvPQPd69i1J… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsmbMJqYIDNgSwPXPr6ViG81qfL84VOUzLLWRVypl1TpTNTnc33qoJZBWyMzYoj7eE0S04GpE6hCN2/IZOb… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAz9uNoVX3mpkSg4RgV+4NmFrT6n64XqP+56YkbCTJG5p9+O5McRoVkfTdVTSi7mISgFWmiKrH034wNOi66T…
selectors probed - selector1:
Certificate (current)
WR3
Expires in 28 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.jquery.com *.property.nhs.uk *.nhs.uk *.microsoft.com *.dynamics.com *.reciteme.com *.cloudflare.com *.visualwebsiteoptimizer.com *.vimeocdn.com *.fonts.net *.azureedge.net *.licdn.com *.hotjar.com *.sharethis.com *.clarity.ms *.googleoptimize.com *.aspnetcdn.com *.facebook.net *.typekit.net *.datadoghq-browser-agent.com *.ggpht.com cdn.jsdelivr.net *.vimeo.com *.umbraco.com *.youtube.com *.google.co.uk *.google.com *.googletagmanager.com *.google-analytics.com *.googlesyndication.com *.googleadservices.com *.gstatic.com *.googleapis.com *.bing.com *.facebook.com *.facebook.net *.twitter.com *.linkedin.com data: wss: blob:;- strict-transport-security
max-age=31536000; includeSubDomains;
Links to (4)
- linkedin.com×2
- openspace.nhs.uk×2
- vimeo.com×2
- x.com×2