carepa.se
HTML metadata
Technology
- CDN
- Cloudflare
- jQuery
- 1.11.0 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (7)
- code.jquery.com×4
- fonts.googleapis.com×2
- dev.visualwebsiteoptimizer.com×1
- dl.episerver.net×1
- fonts.gstatic.com×1
- ratinglogo.bisnode.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- adi.ns.cloudflare.com
- scott.ns.cloudflare.com
- MX
-
- 10 carepa-se.mail.protection.outlook.com
- TXT
-
kor666t2715fpcamrq34echq90
Email authentication strong
- SPF
-
v=spf1 include:spf.protection.outlook.com include:_spf.ixxhosting.se ip4:52.138.139.109 ip4:194.132.16.54 ip4:193.235.46.54 include:spf.mandrillapp.com include:starwebserver.se include:sendgrid.net -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100; rua=mailto:dmarc_customers@ixx.se; ruf=mailto:dmarc_customers@ixx.sepolicy: reject (enforced) - DKIM
-
Show 4 DKIM selectors
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNbJxD4HyPkDhyRYtlwxj/W6tcFFG2fQhmJf9P/SPLRv1uueu8vSrWrEd3A3/mQDttPgAddkpAOHKMKUFrsW… - k1:
k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbNrX2cY/GUKIFx2G/1I00ftdAj713WP9AQ1xir85i89sA2guU0ta4UX1Xzm06XIU6iBP41VwmPwBGRNofhBVR+e6WHUo… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA18OlD9StQuiDHBrKI9dqgUoPpbFp6/XugNiOyxq4OjEYiuDiLJ4HpfDhYSFdjC4EzFYDxihoRfgSjzZ+nv… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDujYb//bSCKiRKDXwfGXDoacpQ0yIWHJBBzkjISEsVptts2M+KSG5BzI0WzKNxjDAYz4bSUdUVaXd9Ud8g+FxCW0…
selectors probed - selector2:
Certificate (current)
WE1
Expires in 81 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
browsing-topics=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.svea.com https://checkoutapi.svea.com/ https://checkoutapistage.svea.com/ https://googleads.g.doubleclick.net *.excentos.com *.linkedin.com https://gethatch.com *.hotjar.com *.hotjar.io https://cdn-cookieyes.com *.cookieyes.com ws: wss: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bootstrapcdn.com https://www.googleanalytics.com https://www.google-analytics.com https://www.googleoptimize.com https://optimize.google.com https://www.google.com https://googleads.g.doubleclick.net https://www.google.com/pagead https://www.google.com/pagead/landing *.google.com https://gethatch.com *.hotjar.com *.hotjar.io *.svea.com https://checkoutapi.svea.com/ https://checkoutapistage.svea.com/ https://static.zdassets.com https://ekr.zdassets.com https://*.zendesk.com https://dc.services.visualstudio.com https://az416426.vo.msecnd.net https://code.jquery.com http://code.jquery.com https://maxcdn.bootstrapcdn.com *.jquery.com *.facebook.com *.facebook.net *.episerver.net *