sdttrainingacademy.co.uk

.uk crawl

First seen 2026-04-21 · Last seen 2026-05-12 · ok HTTP/1.1 200 2614 ms crawled 2026-05-15

GB · 5.101.147.13 · AS42831 UK Dedicated Servers Limited

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
Home - Society of Dairy Technology Academy
Language
en-GB
Generator
Divi Child v.1.0.0
Canonical
https://sdttrainingacademy.co.uk/
Feeds

Open Graph

url
https://sdttrainingacademy.co.uk/
title
Home - Society of Dairy Technology Academy
locale
en_GB
site name
Society of Dairy Technology Academy

Technology

Server
nginx
CMS
WordPress
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.googleapis.com×2
  • www.google.com×2
  • static.zdassets.com×1

Social

Contact

Phone

Registration

Registrar
Tucows Inc t/a Tucows
Created
2020-05-26
Expires
2026-05-26 5 days left
Updated
2025-05-21
Name servers
  • ns1.sdttrainingacademy.co.uk.
  • ns2.sdttrainingacademy.co.uk.

DNS records live

NS
  • ns1.sdttrainingacademy.co.uk
  • ns2.sdttrainingacademy.co.uk
MX
  • 10 mail.sdttrainingacademy.co.uk

Email authentication strong

SPF
v=spf1 +a +mx +a:sdt2.totrain.co.uk -all
strict (-all)
DMARC
v=DMARC1; adkim=s; aspf=s; p=quarantine
policy: quarantine
DKIM
  • default: v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC93ho6pCHNGcQu8hVfU5EAnBaTatd0GOjzFeXRIcYQm/YRc5XUn6sFP1v6HP42kx7Rxyi6dW9Ai+sf42EsaA+wZSL3e…
selectors probed

Certificate (current)

R12
from 2026-03-30 to 2026-06-28
Expires in 38 days

HTTP security headers

Header hygiene 45/100 Checked live page: https://sdttrainingacademy.co.uk/

present
  • content-security-policy
  • permissions-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
Header values
permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
content-security-policy
script-src * 'self' 'unsafe-inline' 'unsafe-eval' wistia.com youtube.com blob:

Links to (4)

Linked from (1)