thevds.co.uk
HTML metadata
Technology
- CDN
- Cloudflare
- Analytics
-
- Cloudflare Insights
- Google Tag Manager
Third-party hosts loaded (5)
- cdnjs.cloudflare.com×1
- static.cloudflareinsights.com×1
- www.freeprivacypolicy.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- amit.ns.cloudflare.com
- nadia.ns.cloudflare.com
- MX
-
- 10 eu-smtp-inbound-1.mimecast.com
- 10 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 6 TXT records
ukv51lbdrtov52be5ani8u9k9a0ed1fe018a788441249d0e4278a7170e6dlhiivd03si17lnvb9rtnmjdkacup7a90s364c81ur840o69r3ue0v0tec2r68rhlkeutulknjidggoogle-site-verification=SRiX78XjcvYzkwUU93BHNAKnArx3r5rMtKBQ3c9YH8o
Email authentication strong
- SPF
-
v=spf1 redirect=_sb9d6a2ye.sdmarc.netno all qualifier - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:a.b9d6a2ye@sdmarc.netpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 81 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'none';connect-src 'self' www.google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com;frame-src 'self' www.google.com;img-src 'self' data: media.vdsnet.co.uk *.google-analytics.com *.googletagmanager.com cdnjs.cloudflare.com;font-src 'self' cdnjs.cloudflare.com;style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com;script-src 'self' 'unsafe-inline' www.google.com *.googletagmanager.com www.gstatic.com www.freeprivacypolicy.com cdnjs.cloudflare.com;- strict-transport-security
max-age=31536000; includeSubDomains; preload