westlancs.gov.uk
HTML metadata
Technology
- jQuery
- 3.6.0
- Ads
-
- Meta Pixel
- Social widgets
-
- Twitter Widget
Third-party hosts loaded (8)
- ajax.googleapis.com×1
- connect.facebook.net×1
- maps.google.com×1
- platform.twitter.com×1
- s7.addthis.com×1
- uk1.siteimprove.com×1
- www.browsealoud.com×1
- www.google.com×1
Social
DNS records live
- NS
-
- ans1.cw.net
- ans2.cw.net
- MX
-
- 5 westlancs-gov-uk.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
tp4rcy7c6sb08zs0t3mbpnc4dwr8smx1_ah5g969e8nt3nn31frjzg7kvzcqwpy1_wpb6gqejtjdz3adff9fwlwehehq9uqd_hmak4zl74t51ca7yprq4r4ys0ny6wck
- Verified for
-
- Apple
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a include:_spf.stonefish.co.uk include:smtp.evolutive.co.uk ip4:20.162.106.173/32 ip4:85.210.65.49/32 ip4:91.194.152.48/28 ip4:195.92.195.234/32 ip4:195.92.195.233/32 ip4:82.33.221.20 ip4:195.92.193.221/32 ip4:195.92.193.207/32 include:mail1.btlancashire.co.uk include:mail2.btlancashire.co.uk ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@btlancashire.co.uk; ruf=mailto:dmarc@btlancashire.co.uk; fo=1; pct=10; adkim=r; aspf=rpolicy: none (monitoring only) · pct=10 - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqx8DWTBtjpRNAtqEFJtGU7NMVrtp8ycej9mTYlVUU+SQ4WUJ05tcWs14NKipn2QTtfrz/fkKYLaGMQYQA2I… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDrbnMSKmCFr5juFpgosQzSlF/7PKaA0e+B+6QzKJjAnS1tlb5OuePvwTS6Azz5NYFYWTUIcHyVuF+L5EjL6U…
selectors probed - selector1:
Certificate (current)
DigiCert Global G2 TLS RSA SHA256 2020 CA1
Expires in 224 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob: *.westlancs.gov.uk;style-src 'self' *.westlancs.gov.uk fonts.googleapis.com *.google.com *.twitter.com *.twimg.com www.browsealoud.com plus.browsealoud.com 'unsafe-inline';script-src 'self' *.westlancs.gov.uk *.westlancsdc.local www.googleapis.com ajax.googleapis.com maps.googleapis.com *.google.com www.google-analytics.com ssl.google-analytics.com www.googletagmanager.com *.addthis.com *.addthisedge.com *.siteimprove.com *.siteimproveanalytics.com *.siteimprove.net *.siteimproveanalytics.io www.browsealoud.com plus.browsealoud.com *.speechstream.net wikisum.texthelp.com *.facebook.net *.facebook.com *.ads-twitter.com *.twitter.com *.ucpages.co.uk *.twimg.com 'unsafe-inline' 'unsafe-eval';img-src 'self' *.westlancs.gov.uk www.googleapis.com maps.googleapis.com *.google.com maps.gstatic.com ssl.gstatic.com www.google-analytics.com ssl.google-analytics.com *.siteimprove.com *.siteimproveanalytics.com *.siteimprove.net *.siteimproveanalytics.io *.addthis.com data:- strict-transport-security
max-age=31536000; includeSubDomains; preload