smababy.co.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
Third-party hosts loaded (3)
- apps.nestle.co.uk×1
- unpkg.com×1
- www.smababy.ie×1
Social
Registration
- Registrar
- Nom-IQ Limited t/a Com Laude
- Created
- 2011-08-17
- Expires
- 2026-08-17 88 days left
- Updated
- 2025-07-18
- Name servers
-
- amsdns1.nestle.com.
- aoadns1.nestle.com.
- ctrdns1.nestle.com.
- eurdns1.nestle.com.
DNS records live
- NS
-
- amsdns1.nestle.com
- aoadns1.nestle.com
- ctrdns1.nestle.com
- eurdns1.nestle.com
- MX
-
- 10 custmx.cscdns.net
- TXT
-
Show 5 TXT records
zq1bshs9b3lr4hczrtdkzd1b4bfvjvv5_05e9ukk6xbvg3jqnnn803ilagcfwdzsf4f53jd9b231dt4h15m8wtyprz782zzkt420rh316pgc497lr5d6g35z4bp351hlwyqydp84chvvct18zhhf2w1b0b4h8lwy
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.emailpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 38 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.sessioncam.com *.cloudfront.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.smababy.co.uk *.cloudfront.net *.sessioncam.com *.hypemarks.com *.krxd.net *.googleapis.com *.googletagmanager.com *.google-analytics.com *.google.com *.google.co.uk *.newrelic.com *.betrad.com bam.nr-data.net static.addtoany.com *.cloudflare.com brand-ecommerce-assets.fusepump.com *.youtube.com s.ytimg.com *.evidon.com code.jquery.com *.cloudfront.net *.serving-sys.com 7225833.collect.igodigital.com connect.facebook.net stats.g.doubleclick.net *.gstatic.com *.cloudfront.net *.sessioncam.com *.gigya.com *.bazaarvoice.com *.amazonaws.com *.adimo.co *.iesnare.com *.polyfill.io *.cdns.eu1.gigya.com *.gigya.com *.nestle.co.uk *.nestle.com *.pinimg.com *.salesforceliveagent.com *.force.com *.salesforce.com *.cookielaw.org *.onetrust.com *.cookiepro.com *.amazon-adsystem.com *.yimg.com *.salesforce-sites.com *.pinterest.com unpkg.com *.windows.net *.tiktok.com *.jsdelivr.net *.ownid.com *.- strict-transport-security
max-age=1000, max-age=300