senta.co
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Statcounter
Third-party hosts loaded (5)
- fast.wistia.com×2
- pro.fontawesome.com×2
- c.statcounter.com×1
- www.googletagmanager.com×1
- www.statcounter.com×1
Social
Contact
- Phone
- Address
- st of practice management software.NameEmailCompanyContactSupport ticket(+44) 3442
DNS records live
- NS
-
- ns-1487.awsdns-57.org
- ns-1685.awsdns-18.co.uk
- ns-358.awsdns-44.com
- ns-634.awsdns-15.net
- MX
-
- 1 eu-smtp-inbound-1.mimecast.com
- 5 eu-smtp-inbound-2.mimecast.com
- TXT
-
facebook-domain-verification=25jwg7it79a7gvve6dlt7ipe87sk97google-site-verification=f8IckRfQScbTdDd7qMzpqlw7EnapFCoeW79Vf57pgFAMS=ms56556252
Email authentication partial
- SPF
-
v=spf1 include:_spf.google.com include:amazonses.com include:email.freshdesk.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCGsuVKG4jkIxGgT9WLfu9KjJkocZgG8uGZjriMRx1xFnybuL2T+zZYjfhKOva0C/DoCF47UhAddXzvRK+ixe… - s1:
v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2Fe1ZQyl4GqIeXVtTT2whFeKAYK+3LVGXJ/bHMOHCRUer++LCQJiGT2b/pxw/WoCDsgp0hymTGO/zSzJ… - s2:
v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkuBdUnAL/jUe0Vd2Fr224B031tXylKmuUm7rlRgnZ4QOqdJOoJTYeVit6glYhZagrM3ndCzKlu8kKvjM…
selectors probed - google:
Certificate (current)
Amazon RSA 2048 M02
Expires in 134 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src https: *.hotjar.com *.hotjar.io *.wistia.com *.wistia.net 'self' 'unsafe-inline' 'unsafe-eval'; font-src https: *.hotjar.com *.hotjar.io *.wistia.com *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline' 'unsafe-eval'; img-src https: *.hotjar.com *.hotjar.io *.tawk.to cdn.jsdelivr.net tawk.link *.iubenda.com *.wistia.com *.wistia.net data: 'self' 'unsafe-inline' 'unsafe-eval'; script-src blob: https: 'self' *.hotjar.com *.hotjar.io *.iubenda.com *.wistia.com *.wistia.net *.tawk.to cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval'; connect-src https: *.litix.io *.wistia.com *.tawk.to wss://*.tawk.to *.hotjar.com *.hotjar.io wss://*.hotjar.com; frame-src https: 'self' blob: *.hotjar.com *.hotjar.io *.tawk.to fast.wistia.com fast.wistia.net; style-src blob: https: 'self' *.hotjar.com *.hotjar.io *.iubenda.com fast.wistia.com *.tawk.to fonts.googleapis.com cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval'; media-src * blob: data: https: *.wistia.com *.wistia.net 'self' 'unsafe-inl- strict-transport-security
max-age=63072000; includeSubDomains; preload