autismeforeningen.dk
HTML metadata
Technology
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (1)
- consent.cookiebot.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.curanet.dk
- ns2.curanet.dk
- MX
-
- 10 mx1.onlinemail.io
- 20 mx2.onlinemail.io
Email authentication weak
- SPF
-
v=spf1 a mx ip4:168.245.35.169 include:sendgrid.net ~allsoftfail (~all) - DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwPcoXHDOgnotmsO+xAUsaWmZurndWDkJM2Z19oszbs3uujeGfB4vCJMHGbHR3vy6BxbEzoD0KaPy6lHNIe… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDnqx4IHrjkNLnhpwH5xaDxsePCOSBmmKNys/O/Qn7WfzZBn2zxflJ+qh/KoSD2k3YQdi8tkN+uhZOwhToABUnafK…
selectors probed - s1:
Certificate (current)
R12
Expires in 84 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SameOrigin- permissions-policy
accelerometer=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), autoplay=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), fullscreen=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), geolocation=(), gyroscope=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), keyboard-map=*, magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), publickey-credentials-get=*, screen-wake-lock=(), sync-xhr=*, usb=(), web-share=(self "https://www.youtube.com" "https://www.youtube-nocookie.com"), xr-spatial-tracking=(), clipboard-read=*, clipboard-write=*, gamepad=()- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'self' 'unsafe-inline' *.youtube.com *.youtube-nocookie.com *.google-analytics.com *.googletagmanager.com *.cookiebot.com *.piwik.pro;object-src 'none';style-src 'self' 'unsafe-inline' *.youtube.com *.youtube-nocookie.com *.googleapis.com *.cookiebot.com;img-src 'self' data: https:;media-src 'self';frame-src 'self' *.cookiebot.com *.vimeo.com *.youtube.com *.youtube-nocookie.com;font-src 'self';connect-src 'self' *.googleapis.com *.google-analytics.com *.googletagmanager.com *.cookiebot.com *.doubleclick.net *.matomo.cloud *.piwik.pro;worker-src blob:;upgrade-insecure-requests;block-all-mixed-content- strict-transport-security
max-age=31536000; includeSubDomains; preload
autismeforeningen.dk