bwhhotels.no
HTML metadata
Technology
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- images.ctfassets.net×25
- script.crazyegg.com×1
- use.typekit.net×1
- www.bwhhotels.se×1
- www.googletagmanager.com×1
Social
Registration
- Registrar
- GROUP.ONE NORWAY AS
- Created
- 2023-04-20
- Updated
- 2026-04-20
- Name servers
-
- ns01.no.brand.one.com
- ns02.no.brand.one.com
DNS records live
- NS
-
- ns01.no.brand.one.com
- ns02.no.brand.one.com
- MX
-
- 0 bwhhotels-no.mail.protection.outlook.com
- Verified for
-
- 1Password
- Adobe
- Atlassian
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt4th9Ce9/vSZvg8yE7L3wk7UF+l2SKQLeK9RwqM6y1wDwdMojSRXLocSR2Tymw4XI8lYsyCIEt6R0x… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxTs5Djb6rKLxF713HyxjgLiiWlx95NSL3AyNSflRre06ymtDsDoOcIKCry+SGXyaQH/1Z/unzR5H3j…
selectors probed - selector1:
Certificate (current)
Thawte TLS RSA CA G1
Expires in 164 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-content-type-options
nosniff- content-security-policy
child-src 'self'; default-src 'self' https://*.google.com https://*.googleapis.com https://*.stripe.com https://sc-static.net https://tr.snapchat.com https://*.googletagmanager.com; frame-src 'self' https://*.crazyegg.com https://*.stripe.com https://*.google.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu https://*.sj.se https://td.doubleclick.net/ https://tr.snapchat.com https://*.googletagmanager.com; worker-src 'self' blob:; connect-src 'self' ws://localhost:* http://localhost:4000/graphql https://*.bestwestern.se/graphql https://*.bestwestern.com https://*.crazyegg.com https://content.web.bwhhotelgroup.com/stripe-pk.json https://*.doubleclick.net/ https://*.g.doubleclick.net https://*.google.com https://*.google.no https://*.google.dk https://*.google.se https://*.analytics.google.com https://*.googleapis.com https://*.googletagmanager.com https://*.googlesyndication.com https://*.google-analytics.com https://consentcdn.cookiebot.com https://consentcdn.cookieb- strict-transport-security
max-age=31536000; includeSubDomains