uclhprivatehealthcare.co.uk
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Drupal
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- www.uclh.nhs.uk×5
- www.googletagmanager.com×2
- translate.google.com×1
- www.cqc.org.uk×1
Social
Contact
- Phone
Registration
- Registrar
- Gandi
- Created
- 2020-02-14
- Expires
- 2028-02-14 634 days left
- Updated
- 2025-01-30
- Name servers
-
- ns-106-a.gandi.net.
- ns-164-c.gandi.net.
- ns-204-b.gandi.net.
DNS records live
- NS
-
- ns-106-a.gandi.net
- ns-164-c.gandi.net
- ns-204-b.gandi.net
- MX
-
- 10 spool.mail.gandi.net
- 50 fb.mail.gandi.net
Email authentication weak
- SPF
-
v=spf1 include:_mailcust.gandi.net ?allneutral (?all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 218 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN, SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self'; frame-src 'self' https://app.powerbi.com/ https://studio.eu.screencloud.com/ https://screencloud.com/ https://*.tickettailor.com https://new.express.adobe.com/webpage/static/embed/embed.js *.webspellchecker.net/ https://w.soundcloud.com/ *.adobe.com/ *.nhs.uk/ *.facebook.com/ *.youtube.com/ *.vimeo.com/ *.google.com/ *.googleapis.com/; script-src 'self' https://cdn.jsdelivr.net https://staticnew-prod.topdoctors.co.uk 'unsafe-inline' 'unsafe-eval' https://studio.eu.screencloud.com/ https://screencloud.com/ https://cdn.tickettailor.com/js/widgets/min/widget.js *.tickettailor.com https://new.express.adobe.com/webpage/static/embed/embed.js https://moneypennychat.appspot.com/chatjs/ https://www.doctify.com/ *.webspellchecker.net/ https://widget.surveymonkey.com/ *.adobe.com/ https://cdnjs.cloudflare.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://connect.facebook.net/ https://feeds.trac.jobs/ *.google.com *.googleapis.com *.gstatic.com *.- strict-transport-security
max-age=0; includeSubDomains; preload