safestore.co.uk
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Cloudflare Insights
- Fonts
-
- Google Fonts
Third-party hosts loaded (10)
- fonts.googleapis.com×4
- kit.fontawesome.com×3
- cdn.jsdelivr.net×2
- www.google.com×2
- cdnjs.cloudflare.com×1
- fonts.gstatic.com×1
- img.youtube.com×1
- static.cloudflareinsights.com×1
- widget.trustpilot.com×1
- www.gstatic.com×1
Social
Contact
- Address
- Brittanic House, Stirling Way, WD6 2BT, Borehamwood, Hertfordshire, GB
DNS records live
- NS
-
- ns1.netnames.net
- ns2.netnames.net
- ns5.netnames.net
- ns6.netnames.net
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
sophos-domain-verification=d30461cebd8ba3c1ea4a1685accdedaf1174a6ed87b2f133731d79bef9aff796
- Verified for
-
- Apple
Email authentication strong
- SPF
-
v=spf1 include:_netblocks.mimecast.com ip4:5.57.59.197 ip4:185.35.248.215 include:spf.protection.outlook.com include:spf.rpost.net ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:54908ff1bac8391@rep.dmarcanalyzer.com; ruf=mailto:54908ff1bac8391@for.dmarcanalyzer.com; fo=1;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: *.fontawesome.com *.stripe.com *.reddit.com;script-src 'self' *.elfsightcdn.com elfsightcdn.com *.elfsight.com *.trustpilot.com *.aspnetcdn.com *.bootstrapcdn.com blob: *.cloudflare.com *.cloudflareinsights.com *.fontawesome.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com googleads.g.doubleclick.net *.googletagmanager.com googletagmanager.com *.gstatic.com *.jsdelivr.net *.segment.com unpkg.com *.cookiehub.eu *.contentsquare.net *.hotjar.com *.dwin1.com *.facebook.net *.bing.com *.livechatinc.com *.roeyecdn.com *.awin1.com *.dwin1.com www.redditstatic.com *.stripe.com *.webtrends-optimize.com companyinspired.com *.webtrends-optimize.workers.dev 'unsafe-eval' 'unsafe-inline';style-src 'self' *.bootstrapcdn.com *.cloudflare.com *.continual.ly *.crazyegg.com *.fontawesome.com *.google.com *.googleapis.com *.googletagmanager.com googletagmanager.com *.jsdelivr.net *.linearicons.com rsms.me unpkg.com *.cookiehu- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin
Links to (12)
- easybox.it×1
- facebook.com×1
- instagram.com×1
- linkedin.com×1
- ohmybox.es×1
- pinterest.com×1
- safestore.com×1
- ssauk.com×1
- trustpilot.com×1
- unepieceenplus.com×1
- x.com×1
- youtube.com×1