byggtjanst.se
HTML metadata
Technology
- CDN
- Azure Front Door
- JS framework
- Angular 20.3.16
- Analytics
-
- Google Analytics
- Google Tag Manager
- Fonts
-
- Google Fonts
- Social widgets
-
- YouTube Embed
Third-party hosts loaded (10)
- fonts.gstatic.com×3
- www.youtube.com×3
- fonts.googleapis.com×2
- a.omappapi.com×1
- api.omappapi.com×1
- az416426.vo.msecnd.net×1
- dc.services.visualstudio.com×1
- js-eu1.hsforms.net×1
- www.google-analytics.com×1
- www.googletagmanager.com×1
DNS records live
- NS
-
- ephemera.nmugroup.se
- origo.nmugroup.com
- unit.nmugroup.com
- vertex.nmugroup.se
- MX
-
- 10 byggtjanst-se.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
byggtjanstdevfront.azurewebsites.netJOoElTk3GjhbMUndZ+jA3gUqi0grWXx2juwxO7e1FTDpsx553h1da43QnPJAozXNgffU5r40Inzh4JA6YKciZQ==07sbny4wn89dknl311zq7wqbzgc2y4znbyggtjanstdev.azurewebsites.net
- Verified for
-
- Adobe
- Anthropic
- Apple
- Citrix
- Meta
- Microsoft 365
- OpenAI
Email authentication partial
- SPF
-
v=spf1 ip4:88.131.72.236 ip4:88.131.72.238 ip4:80.72.8.176/29 ip4:193.44.77.163 ip4:89.46.81.172 include:spf.protection.outlook.com include:_spf.lyyti.fi include:_spf.netigate.se include:27131709.spf03.hubspotemail.net include:spf-eu.emailsignatures365.com -allstrict (-all) - DMARC
-
v=DMARC1;p=none;sp=none;adkim=s;aspf=s;fo=1:d:s;rf=afrf;ri=86400;pct=100;rua=mailto:dmarc-report@byggtjanst.se;ruf=mailto:dmarc-report@byggtjanst.sepolicy: none (monitoring only) · sp=none - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDa0DDvITJIYBAEOFUawCSHx6oHLEUHNgcqN7x4bJsDhgBnF6PkKzAAdoL3HZ98+4lKJxeNkQytwO/hJ8etWB… - selector2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArIKXDK+JE0tqVvUs5TSa2ADJkzM+ld4qxMU44V1jUFYp1L49WNlHGkPKZlM3rMYEeh3uRnj8DXwRlU…
selectors probed - selector1:
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 99 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' https:;script-src 'self' https: 'unsafe-inline' 'unsafe-eval';connect-src 'self' https: wss:;style-src 'self' https: 'unsafe-inline';object-src 'none';frame-ancestors 'self' https://*.byggtjanst.net/ https://*.byggtjanst.se/- strict-transport-security
max-age=15552000; includeSubDomains