psuk.co.uk
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (2)
- consent.cookiebot.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1-06.azure-dns.com
- ns2-06.azure-dns.net
- ns3-06.azure-dns.org
- ns4-06.azure-dns.info
- MX
-
- 10 mail01.phoenixgroup.eu
- 10 mail02.phoenixgroup.eu
- 10 mail03.phoenixgroup.eu
- 10 mail04.phoenixgroup.eu
- TXT
-
globalsign-domain-verification=209001F1DEB72CDA85CE3043E900F33Cgoogle-site-verification=3VSfaa3aEvLTPlANHjMo_EIucYW_Kv7G2lKAFNYnEoc
Email authentication strong
- SPF
-
v=spf1 include:_u.psuk.co.uk._spf.smart.ondmarc.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; sp=reject; rua=mailto:3fb658a1@inbox.eu.redsift.cloud; ruf=mailto:3fb658a1@inbox.eu.redsift.cloud; adkim=r; aspf=r; fo=0; rf=afrf; ri=3600policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 61 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' psuk.co.uk; script-src 'self' 'unsafe-inline' 'unsafe-eval' consent.cookiebot.com consentcdn.cookiebot.com www.googletagmanager.com widget.intercom.io *.intercomcdn.com *.psuk.co.uk recaptcha.net www.gstatic.com; connect-src 'self' wss: gateway.psuk.co.uk *.googlesyndication.com stats.g.doubleclick.com stats.g.doubleclick.net www.google.com analytics.google.com stats.g.doubleclick.com *.intercom.io consentcdn.cookiebot.com region1.google-analytics.com region1.analytics.google.com; img-src 'self' data: imgsct.cookiebot.com js.intercomcdn.com downloads.intercomcdn.eu static.intercomassets.eu www.google.ie www.google.co.uk www.googletagmanager.com i.ytimg.com; style-src 'self' 'unsafe-inline'; base-uri 'self'; form-action 'self'; manifest-src 'self'; frame-src 'self' www.googletagmanager.com td.doubleclick.com consentcdn.cookiebot.com td.doubleclick.net recaptcha.net www.youtube.com intercom-sheets.com https://events.psuk.co.uk; font-src 'self' fonts.intercomcdn.com- strict-transport-security
max-age=31536000; includeSubDomains