rowlandspharmacy.co.uk
HTML metadata
Technology
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (4)
- app.hashealth.com×2
- consent.cookiebot.com×1
- static.legitscript.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- ns1-04.azure-dns.com
- ns2-04.azure-dns.net
- ns3-04.azure-dns.org
- ns4-04.azure-dns.info
- MX
-
- 10 mail01.phoenixgroup.eu
- 10 mail02.phoenixgroup.eu
- 10 mail03.phoenixgroup.eu
- 10 mail04.phoenixgroup.eu
- TXT
-
Show 7 TXT records
wb8c96h6h9wfvyz2k2fjx0f6r0mjw5n9nes5st7i9h1m0d34iuecgnj51cfacebook-domain-verification=losq68ahzdym2bhin99cm413n8yij7MS=ms79648811MS=92D131EDD4034784EDA6A86287FFB0B3CC0B122Dte9aqin1jie8odu2t87qsjmel260tori1m1ff05o33bfprdqnk3p
Email authentication strong
- SPF
-
v=spf1 include:_u.rowlandspharmacy.co.uk._spf.smart.ondmarc.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; pct=100; sp=reject; rua=mailto:3fb658a1@inbox.eu.redsift.cloud; ruf=mailto:3fb658a1@inbox.eu.redsift.cloud; adkim=r; aspf=r; fo=0; rf=afrf; ri=3600policy: reject (enforced) · sp=reject - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 71 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' widget.intercom.io/widget/zvy5mnyd uberall.com *.uberall.com app.hashealth.com *.cookiebot.com connect.facebook.net www.googletagmanager.com api.mapbox.com events.mapbox.com www.gstatic.com recaptcha.net; connect-src 'self' gateway.rowlandspharmacy.co.uk *.uberall.com *.mynuasolution.com consentcdn.cookiebot.com connect.facebook.net www.facebook.com www.googletagmanager.com www.google-analytics.com *.googlesyndication.com capig.stape.cc analytics.google.com stats.g.doubleclick.net www.google.com region1.analytics.google.com region1.google-analytics.com api.mapbox.com events.mapbox.com *.hashealth.com; img-src 'self' data: locator.uberall.com www.facebook.com *.cookiebot.com api.mapbox.com www.google.ie www.google.co.uk www.googletagmanager.com static.legitscript.com; style-src 'self' 'unsafe-inline' hello.myfonts.net; base-uri 'self'; form-action 'self'; font-src 'self' locator.uberall.com; frame-src 'self' consentcdn.- strict-transport-security
max-age=31536000; includeSubDomains