yorkshirehousing.co.uk
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (2)
- ajax.googleapis.com×1
- www.googletagmanager.com×1
Social
Contact
- Address
- The Place, 2 Central Place, LS10 1FB, Leeds, Yorkshire, United Kingdom
DNS records live
- NS
-
- dns1.ccsleeds.com
- dns2.ccsleeds.com
- dns3.ccsleeds.com
- MX
-
- 0 eu-smtp-inbound-1.mimecast.com
- 0 eu-smtp-inbound-2.mimecast.com
- TXT
-
Show 4 TXT records
amazon-business-verification=b374e5004155963e7907e51510116e95fe5c9e34c9f92e4f3102eaffa2362b340ed1fe018a09851916303f42078988b5dd297a81f0ud9NBVMzHHxYr+g7SR4IwI24i0EMGRwjMW+oG4CvZhBzsy/Kf5xAU27XQoeRin4zDegY21rkMhNQJKnxSiyxGQ==have-i-been-pwned-verification=2441bfb6328bd0ab5d32816e8e17ec37
- Verified for
-
- Brevo
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 a include:eu._netblocks.mimecast.com include:spf1.yorkshirehousing.co.uk include:spf2.yorkshirehousing.co.uk -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:8e392854aeee485@rep.dmarcanalyzer.com; ruf=mailto:8e392854aeee485@for.dmarcanalyzer.com; fo=1;policy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCw5bGFiYOwKdrrnv/8jMVsI9l9V5sauPGvtVJ2flP8pj6jTI+vZYgaPOZPXdvJ6IIT/JfijEw696YN3VNnSa… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1gOmFfGa0k/qS5VE9I84bb4CAoSHGqX0GbzeMdKqb9b47cn+9DGcph9q46/ORzo6Uar6iN9ZH1gaRecbzE… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvEaxG6t07nJSmYnRpaACXNbIf4gtG24GmoELdh3VSOBF2YLU10ezx95V8jxqDVsAwBALqXYKcSoYm/Qlrq…
selectors probed - selector2:
Certificate (current)
Sectigo Public Server Authentication CA DV R36
Expires in 297 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' packages.umbraco.org our.umbraco.org;script-src 'self' code.jquery.com ajax.googleapis.com *.google.com maps.google.com www.googletagmanager.com *.gstatic.com www.google-analytics.com maps.googleapis.com *.civiccomputing.com m3central.net play.google.com www.youtube-nocookie.com app.plentific.com *.reciteme.com 'unsafe-inline';style-src 'self' cdn.jsdelivr.net fonts.googleapis.com *.google.com app.plentific.com *.reciteme.com 'unsafe-inline';connect-src 'self' maps.googleapis.com *.civiccomputing.com *.google-analytics.com *.google.com *.doubleclick.net play.google.com www.youtube-nocookie.com app.plentific.com *.reciteme.com;font-src 'self' fonts.gstatic.com app.plentific.com *.reciteme.com;img-src 'self' yorkshirehousingwebsite.blob.core.windows.net www.google-analytics.com maps.gstatic.com maps.google.com img.youtube.com data: *.google.co.uk *.google.com app.plentific.com *.reciteme.com;media-src 'self' www.youtube.com player.vimeo.com play.google.com www.youtube-- strict-transport-security
max-age=63072000; includeSubDomains; preload