serc.ac.uk
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
- Google Fonts
Third-party hosts loaded (8)
- kendo.cdn.telerik.com×61
- kit.fontawesome.com×2
- dujantdza7z0f.cloudfront.net×1
- fonts.googleapis.com×1
- translate.google.com×1
- unpkg.com×1
- use.typekit.net×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns10.ja.net
- ns11.ja.net
- ns12.ja.net
- MX
-
- 10 serc-ac-uk.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
firebase=skys-mobile-gamehibp-verify=dweb_t5usn0c364g683jbz4gfocon60zmjVdAjw36TbrV95mJgDKfXRVgUca31T4wiCLyfRb27VFo1Wmtrc0P9H12icHl8WAxvVqQcmgMKOf/kbiSPA==v=verifydomain MS=ms77118548
- Verified for
-
- Adobe
- Microsoft
Email authentication strong
- SPF
-
v=spf1 a mx a:bulkmail.serc.ac.uk ip4:212.219.94.60 ip4:212.219.247.70 ip6:2603:10a6:20b:313::32 include:spf.protection.outlook.com include:servers.ebsnd.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:logging@serc.ac.uk; ruf=mailto:logging@serc.ac.uk; fo=1; pct=100; adkim=s; aspf=spolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4qta+zFeJvJihTs5vlOJsGHuuqecWd8qXDXochcPKIZ5PtcdOINyE9PgrM2JQSaGCniHBOx6dujx2w… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC4d+I/8z4ffHwGNPdxtR6Gcoc0qiCj49YTzeCGTuMAtgF0mGkgOtY/RZkan7tXi3T5/na+8p5l7zbGwOfYUL… - smtpapi:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed - selector1:
Certificate (current)
GeoTrust G5 TLS RSA4096 SHA384 2022 CA1
Expires in 136 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'self' ws: wss: 'unsafe-inline' 'unsafe-eval' data: blob: *.serc.ac.uk *.cloudflare.com *.cloudfront.net surveyjs.azureedge.net *.licdn.com newsapi.org *.doubleclick.net *.youtube.com *.microsoft.com *.clarity.ms *.bing.com *.microsoftonline.com *.google-analytics.com *.googleadservices.com *.google.com *.google.co.uk *.googletagmanager.com themes.googleusercontent.com *.linkedin.com *.facebook.com *.facebook.net *.aspnetcdn.com *.jquery.com *.fontawesome.com *.bootstrapcdn.com *.jsdelivr.net *.googleapis.com *.gstatic.com *.telerik.com *.typekit.net *.typekit.com *.visualstudio.com *.msecnd.net vjs.zencdn.net unpkg.com *.ally.ac *.gravatar.com *.linkedin.oribi.io *.stackadapt.com *.cdn.office.net *.moodle.org *.dotdigital-pages.com *.proquest.com *.turnitinuk.com *.clickview.com *.clickview.co.uk *.clickview.net *.clickview.com.au clickv.ie *.safetyhub.com *.webspellchecker.net serc2-my.sharepoint.com serc2.sharepoint.com autopilotmanager-uz2wyi5szzt3g.azurewebsites.net *.- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (13)
- youtube.com×1
- twitter.com×1
- tiktok.com×1
- sharepoint.com×1
- office365.com×1
- microsoft.com×1
- m.me×1
- linkedin.com×1
- instagram.com×1
- facebook.com×1
- campaign.gov.uk×1
- bsky.app×1
- accessable.co.uk×1