backe.no
HTML metadata
Technology
- Server
- nginx
- CMS
- Next.js
Third-party hosts loaded (2)
- policy.app.cookieinformation.com×1
- www.google.com×1
Social
DNS records live
- NS
-
- a.ns.isp.as2116.net
- b.ns.isp.as2116.net
- c.ns.isp.as2116.net
- d.ns.isp.as2116.net
- MX
-
- 10 backe-no.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
JzOP6YvE1PxaIVy8tOwseMji/2KT4SM3XIPVYBvHDlC4nW8hG0UhNOZ+aUVhJssT9mabKPYxUCw8q/QZjiYjfA==a8ca20ee3da1f08766351ed1e0e8eee41bf4690080b2aaa05bfd524791e43c47a3065842303da907d6d93e988fb2022e0568706d023145839cecb7abb3fe1e4b6b3529fcb8d67201cd1ecc4d999ca8c88b326a62da804d3ccedc1a401d8376fdmandrill_verify.B37mFyVVRB1INdfS1L9v2g- adobe-sign-verification=a2059db520e9e5ea3bcd5eb940896f0
- Verified for
-
- Apple
- Miro
- Workplace
Email authentication strong
- SPF
-
v=spf1 a:www.backe.no mx include:spf.mandrillapp.com include:_spf.backe_no._d.easydmarc.pro ~allsoftfail (~all) - DMARC
-
v=DMARC1;p=reject;pct=100;rua=mailto:da838ceb4c@rua.easydmarc.eu;ruf=mailto:da838ceb4c@ruf.easydmarc.eu;fo=1;policy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCZfMgYUi+5HpdT27fAcmW22qYldSYskbHJteUdYawN2sS/Dc29us3c7I9DLLWz9JJAsIJ4yHcXqkeqYZy17r… - k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqvVkqECtClAcS4HLuOI5/kOrUfm9HXKuQWaW5CU0Tytxo079yqwUBz8dkRuVOWG16+03q+57V8ztNBHWSt… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDEVjeB2A9eFhly3NG/rAHb5jaeMxvBrH1dVO8SSdaPdWNaz6mgE7NoFejFkERfXTo2PZoc00liz2fazA/PkR7l/K…
selectors probed - selector1:
Certificate (current)
E7
Expires in 30 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=(), midi=(), magnetometer=(), gyroscope=(), payment=(), fullscreen=(self)- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src *; font-src *; frame-src *; frame-ancestors 'none'; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline';- strict-transport-security
max-age=31536000; includeSubDomains; preload