vintagetrains.co.uk

.uk crawl

First seen 2026-04-22 · Last seen 2026-05-18 · ok HTTP/1.1 200 1514 ms crawled 2026-05-15

US · 104.21.50.192 · AS13335 Cloudflare, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Vintage Trains | Birmingham Steam Trains on Britain’s Mainline Railway
Description
Step into the golden age of travel with Birmingham's Vintage Trains. Explore the charm and nostalgia of historic rail journeys. Plan a steam train adventure now
Language
en-US
Canonical
https://vintagetrains.co.uk/

Open Graph

url
https://vintagetrains.co.uk/
title
Vintage Trains | Birmingham Steam Trains on Britain’s Mainline Railway
site name
Vintage Trains
description
Step into the golden age of travel with Birmingham's Vintage Trains. Explore the charm and nostalgia of historic rail journeys. Plan a steam train adventure now

Technology

CDN
Cloudflare
CMS
WordPress

Third-party hosts loaded (5)

  • www.facebook.com×3
  • cdnjs.cloudflare.com×2
  • www.google.com×2
  • fareharbor.com×1
  • stats.wp.com×1

Social

Contact

Email
Phone
Address
670 Warwick Road, B11 2HL, Birmingham, England, GB

Registration

Registrar
Claranet Limited t/a Claranet
Created
1999-09-15
Expires
2026-09-15 118 days left
Updated
2025-09-05
Name servers
  • cody.ns.cloudflare.com.
  • lucy.ns.cloudflare.com.

DNS records live

NS
  • cody.ns.cloudflare.com
  • lucy.ns.cloudflare.com
MX
  • 0 vintagetrains-co-uk.mail.protection.outlook.com
TXT
  • MS=ms36283595
  • ca3-b3646c1d7dc544ea96f251346a844d1f
  • google-site-verification=yXckWI0qfSOXA4FfY4aIlaR1LBVNtbjWm6rH9V8dMKw

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com include:relay.mailchannels.net include:_spf.zen.co.uk ~all
softfail (~all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-03-27 to 2026-06-25
Expires in 36 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://vintagetrains.co.uk/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • cross-origin-opener-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https: http: blob:; font-src 'self' data: https:; connect-src 'self' https: wss:; media-src 'self' https:; object-src 'none'; base-uri 'self'; frame-src 'self' https:; frame-ancestors 'self'
strict-transport-security
max-age=31536000
cross-origin-opener-policy
same-origin-allow-popups

Links to (9)

Linked from (2)