bth.se
HTML metadata
Technology
- JS framework
- React
- Stack
- Java
Third-party hosts loaded (1)
- static.rekai.se×2
Social
Contact
- Phone
DNS records live
- NS
-
- netsrv10.bth.se
- ns3.ltblekinge.se
- sunic.sunet.se
- MX
-
- 10 bth-se.mail.protection.outlook.com
- TXT
-
have-i-been-pwned-verification=19c3c4403754932d91cdfeedde261aea
- Verified for
-
- Adobe
- Apple
- Atlassian
- HARICA
- Meta
- Microsoft
- Microsoft 365
- OpenAI
- Zoom
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com ip4:130.239.8.142 ip4:130.239.8.162 ip4:194.47.129.50 ip4:94.246.96.164 include:spf.abicart.com a mx include:_spf.rulemailer.com ip4:212.85.68.72 -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; sp=reject; pct=100; rua=mailto:dmarc_agg@vali.email; ruf=mailto:postmaster@bth.sepolicy: reject (enforced) · sp=reject - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzTnzL5NC5xGq0ARgDmtOMr9tidkFR77VpkTRAcL43TWGfeBkBZZ8ABCkz1Xwxy025QcUxjcj9P+uv9+pS1w… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArKVY3PHAtesQ3mIgPxM+7QtJAKLXN3xxYmpPYI0Wszbzh63v+OW90sLLRG9q1NOCpkKEf29nmudz+F…
selectors probed - selector1:
Certificate (current)
R12
Expires in 52 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' blob:; script-src 'self' 'unsafe-eval' 'nonce-e6348260-5951-11f1-bcae-0145da09ab04' https://mfstatic.com https://*.rekai.se https://storage.gra.cloud.ovh.net/v1/ https://ebbot.eu/api/ https://svanalytics.piwik.pro/ https://svanalytics.containers.piwik.pro/ https://cdn.ontame.io blob: https://*.bth.se/; img-src 'self' https://*.mediaflowpro.com https://mfstatic.com https://storage.gra.cloud.ovh.net/v1/ https://collector.ontame.io; style-src 'self' 'unsafe-inline' http://localhost:* https://mfstatic.com https://storage.gra.cloud.ovh.net/v1/; font-src 'self' https://mfstatic.com https://storage.gra.cloud.ovh.net/v1/; frame-src 'self' youtube.com www.youtube.com; connect-src 'self' https://*.mediaflow.com https://mfstatic.com https://*.rekai.se https://*.friendlycaptcha.com https://ebbot.eu/api/ wss://ebbot.eu/ https://storage.gra.cloud.ovh.net/v1/ https://svanalytics.piwik.pro/ https://svanalytics.containers.piwik.pro/; media-src https://*.mediaflow.com blob: https://- strict-transport-security
max-age=31536000