treblethree.co.uk
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- CloudFront
- CMS
- Gatsby
- Analytics
-
- Google Analytics
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (3)
- www.googletagmanager.com×3
- fonts.googleapis.com×2
- www.google-analytics.com×2
Social
Contact
Registration
- Registrar
- 20i Ltd
- Created
- 2013-08-23
- Expires
- 2026-08-23 95 days left
- Updated
- 2024-08-23
- Name servers
-
- rayne.ns.cloudflare.com.
- sergi.ns.cloudflare.com.
DNS records live
- NS
-
- rayne.ns.cloudflare.com
- sergi.ns.cloudflare.com
- MX
-
- 10 mx.stackmail.com
Email authentication weak
- SPF
-
v=spf1 include:spf.stackmail.com a mx -allstrict (-all) - DMARC
- not published
- DKIM
-
- s1:
v=DKIM1;k=rsa;h=sha256;n=;s=*;t=s;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqONvWFPeLAbRcM9ewmBA1g3fU5fDiJIPOZcGZDfJLezLRwz0wAAIpKAX1Y/R…
selectors probed - s1:
Certificate (current)
Amazon RSA 2048 M04
Expires in 102 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(*), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(*), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src * 'self' https://*.stripe.com; font-src 'self' https://*.gstatic.com https://*.filestackapi.com; frame-ancestors 'self' https://*.vb.media; frame-src 'self' https://*.stripe.com https://*.paypal.com https://hcaptcha.com https://*.hcaptcha.com https://*.contents.delivery https://*.vb.media https://pitchprint.io https://static.filestackapi.com; img-src 'self' blob: data: https://checkout.stripe.com https://*.paypalobjects.com https://media-library.co.uk https://*.contents.delivery https://*.filestackcontent.com https://*.amazonaws.com https://pitchprint.io https://static.filestackapi.com; manifest-src *; media-src 'self' blob: data: https://media-library.co.uk https://*.contents.delivery https://*.filestackcontent.com; object-src *; script-src 'self' https://media-library.co.uk https://*.contents.delivery https://*.stripe.com https://*.paypal.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.google-analytics.com https://hca- strict-transport-security
max-age=31536000