coor.no

.no crawl

First seen 2026-05-27 · Last seen 2026-05-30 · ok HTTP/1.1 200 1164 ms crawled 2026-05-30

SE · 217.114.94.2 · AS30811 Optimizely AB

Reputation 100/100

Classifying

HTML metadata

Title
Facility Management i Norge | Coor
Language
no
Canonical
https://www.coor.no/

Open Graph

url
https://www.coor.no/
title
Facility Management i Norge | Coor
locale
no

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager

Third-party hosts loaded (3)

  • dc.services.visualstudio.com×1
  • www.googletagmanager.com×1
  • www.juicer.io×1

Social

Contact

Phone
Address
Vollsveien 6, Lysaker, Norway

DNS records live

NS
  • dns1.zaccodigitaltrustlabs.com
  • dns2.zaccodigitaltrustlabs.net
  • dns3.zaccodigitaltrustlabs.se
  • dns4.zaccodigitaltrustlabs.se
  • ns1.zaccodns.com
  • ns2.zaccodns.se
MX
  • 0 coor-no.mail.protection.outlook.com
TXT
  • GekCKKjOc41a/V58NggXtMrXFpJTduFhZJ2zyDDE0/K8pePncrfOmyQScXq3DQDHTF1IoCaXAboQZyx534dzpg==
  • m8zpl1kjh4498dnqk9tbrdzf301nm4cr
  • h7btpsjp79kvsvd78dtfzsb9bty3ww3m
Verified for
  • Microsoft 365

Email authentication strong

SPF
v=spf1 -all
strict (-all)
DMARC
v=DMARC1; p=reject;
policy: reject (enforced)
DKIM
Show 12 DKIM selectors
  • default: v=DKIM1; p=
  • google: v=DKIM1; p=
  • selector1: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFHSUXR+HGQuRpjBHy+FdtMY/4xVeq5xumfaoS9rwBSK7Qq1NLRRDsrwbtMCv4VHm7evJxBBeRFpUkb+6pSL…
  • selector2: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDUvCy6bN46cdY7O8SDVcKDDgf/kiWqkO4xRglOMoW27b3A/wxC/R+DyLSLl+GaU3NGzr7zlzL0HmxW6R4aNM…
  • k1: v=DKIM1; p=
  • k2: v=DKIM1; p=
  • mail: v=DKIM1; p=
  • dkim: v=DKIM1; p=
  • s1: v=DKIM1; p=
  • s2: v=DKIM1; p=
  • mxvault: v=DKIM1; p=
  • smtpapi: v=DKIM1; p=
selectors probed

Certificate (current)

WE1
from 2026-05-06 to 2026-08-04
Expires in 65 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.coor.no/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
same-origin
x-frame-options
SAMEORIGIN
permissions-policy
publickey-credentials-get=(), xr-spatial-tracking=(), screen-wake-lock=(), cross-origin-isolated=(), web-share=(), picture-in-picture=(), keyboard-map=(), encrypted-media=(), display-capture=(), usb=(), serial=(), payment=(), midi=(), microphone=(), magnetometer=(), geolocation=(), camera=(), fullscreen=(), autoplay=(), accelerometer=()
x-content-type-options
nosniff
content-security-policy
report-uri https://www.coor.com/report-endpoints/report; report-to report-endpoint; font-src https://use.typekit.net data: https://fonts.gstatic.com https://widget.lifeinside.io https://static.juicer.io 'self'; img-src https://media.lifeinside.io https://widget.datablocks.se https://app.optimizely.com https://cdn.optimizely.com data: * https://*.googletagmanager.com https://*.google-analytics.com; media-src https://media.lifeinside.io 'self' https://www.juicer.io; script-src https://js-eu1.hsforms.net/forms/embed/v2.js 'unsafe-inline' 'self' https://*.cookiebot.com https://*.lifeinside.io https://tracker.leadenhancer.com https://adsby.bidtheatre.com https://snap.licdn.com https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.googleadservices.com https://*.hotjar.com https://js-eu1.hs-scripts.com https://js-eu1.hsleadflows.net https://js-eu1.hs-banner.com https://js-eu1.hs-analytics.net https://js-eu1.hubspot.com https://js-eu1.usemessages.com ht
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (9)

Linked from (5)