banenoreiendom.no
HTML metadata
Technology
- CDN
- Cloudflare
- Cookie consent
-
- Cookiebot
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (3)
- use.typekit.net×3
- consent.cookiebot.com×1
- p.typekit.net×1
Social
DNS records live
- NS
-
- a.ns.isp.as2116.net
- b.ns.isp.as2116.net
- c.ns.isp.as2116.net
- d.ns.isp.as2116.net
- MX
-
- 10 0.mx.isp.as2116.net
- TXT
-
da043b42517aed0cb430398e77b1d554b1c624e531ce3c47febbaa912bef06dd_30s90tr2k4t67mu2l2y49zs0em0ufai
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 60 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' ; connect-src 'self' https://dc.services.visualstudio.com/v2/track https://pui.episerver.net/api/telemetryconfig https://maps.googleapis.com https://www.google-analytics.com https://region1.google-analytics.com/g/collect https://esp-eu.aptrinsic.com/ https://*.cookieinformation.com/ https://stats.g.doubleclick.net/j https://pagecorrect.monsido.com/ https://tr-shadow.snapchat.com/ https://tr.snapchat.com/ https://stats.g.doubleclick.net/ https://cdn.linkedin.oribi.io/partner/1648329/ https://vc.hotjar.io/sessions/3312419 https://*.hotjar.com https://*.jotform.com wss://eu-sockets.jotform.io https://oc-cdn-public-eur.azureedge.net/livechatwidget/configs/ ws://localhost:* wss://*.hotjar.com/api/v2/client/ws https://content.hotjar.io/ https://csp.withgoogle.com/csp/ https://*.cookiebot.com/ https://*.silktide.com/ https://js.monitor.azure.com/ ; font-src 'self' https://fonts.gstatic.com/ https://*.cloudfront.net/ https://*.typekit.net/; frame-src 'self' https://policy.ap- strict-transport-security
max-age=63072000; includeSubDomains; preload