smahcp.co.uk
HTML metadata
Technology
- Server
- nginx
- CMS
- Drupal
Third-party hosts loaded (4)
- www.smababy.co.uk×2
- apps.nestle.co.uk×1
- unpkg.com×1
- www.smababy.ie×1
Social
Registration
- Registrar
- Nom-IQ Limited t/a Com Laude
- Created
- 2000-10-10
- Expires
- 2026-10-10 142 days left
- Updated
- 2025-09-10
- Name servers
-
- amsdns1.nestle.com.
- aoadns1.nestle.com.
- ctrdns1.nestle.com.
- eurdns1.nestle.com.
DNS records live
- NS
-
- amsdns1.nestle.com
- aoadns1.nestle.com
- ctrdns1.nestle.com
- eurdns1.nestle.com
- MX
-
- 50 mail.wyeth.de
- Verified for
-
Email authentication strong
- SPF
-
v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email;policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 50 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.sessioncam.com *.cloudfront.net; script-src *.cloudfront.net *.sessioncam.com *.hypemarks.com *.krxd.net 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.googletagmanager.com *.google-analytics.com *.google.com *.google.co.uk *.newrelic.com *.betrad.com bam.nr-data.net static.addtoany.com *.cloudflare.com brand-ecommerce-assets.fusepump.com *.youtube.com s.ytimg.com *.evidon.com code.jquery.com *.cloudfront.net *.serving-sys.com 7225833.collect.igodigital.com connect.facebook.net stats.g.doubleclick.net *.gstatic.com *.cloudfront.net ws://*.sessioncam.com wss://*.sessioncam.com *.gigya.com *.bazaarvoice.com *.amazonaws.com *.adimo.co *.iesnare.com *.polyfill.io *.cdns.eu1.gigya.com *.gigya.com *.nescafe.com *.sitepreview.ws *.nestle.co.uk *.nestle.com *.pinimg.com *.salesforceliveagent.com *.force.com *.salesforce.com *.cookielaw.org *.onetrust.com *.cookiepro.com *.amazon-adsystem.com *.yimg.com *.salesforce-sites.com *.pinterest.com unpkg.com *.smababy.co.- strict-transport-security
max-age=1000, max-age=300