econa.no
HTML metadata
Technology
- CDN
- Cloudflare
- jQuery
- 3.4.0 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×3
- code.jquery.com×1
- policy.app.cookieinformation.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- EconaKongens gate 6Postboks 1869 VikaN-0153 OsloTlf. 22 82 80 00support@econa.noOrg nr. 967 371 696
DNS records live
- NS
-
- ns1.upheads.no
- ns2.upheads.com
- ns3.upheads.org
- MX
-
- 1 econa-no.mail.protection.outlook.com
- TXT
-
Show 4 TXT records
simployer_1770886431983_4f7127507c000b3ac786ca1e6c036e074d8a327b52f2d2bc748295848545f3a3259ee9555394d5afe0a1f5b6514490c5ct1fZEQ4BBowxrLUFYl-YBvjCmLlgAfmCkovC-dkNQ0fO1OCbT/cXwUdRcxOXaLqXMiBDy5MSwb8Q/regmYnk=
- Verified for
-
- Dynamics 365
- GlobalSign
- Meta
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx ip4:195.159.253.35 include:_spf.intility.com a:email.services.relatude.com include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:1c907909@mxtoolbox.dmarc-report.com; ruf=mailto:1c907909@forensics.dmarc-report.compolicy: none (monitoring only) - DKIM
-
Show 4 DKIM selectors
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7Bpdtm9bzVyXdkYueaigkgHBF58Oew9CAR9o9Lsk2AN2eCQyE0vePW21k5jucgr2AXS+duneuAlPqPK5YDD… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDLnsigN1cHaIXRYlSfl2N1MG0EHL81XST0JQq0lp9jBX8TjAv6DUSKgHuRPd5YPSZhlXv8ObBUmK3t+qOplw… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwCbzdrHtIYCn4p8lWoeK2G34dy1SuhnZEYX2BJiqCmYmiUlEkIOZvCeIqF2XRf+9PmyqTyie/YWTWn4ab0… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzYn0VfZloFvKQ6fE4CT97TDdv9GBs70Z7oiojG5sVxfShQs+8mNHkul1AvhZaosg6MH5iz9DKFs2HrzHND…
selectors probed - selector1:
Certificate (current)
GlobalSign GCC R3 DV TLS CA 2020
Expires in 150 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self' ws: wss: data:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://js.monitor.azure.com/ https://ajax.aspnetcdn.com/ https://mktdplp102cdn.azureedge.net/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://dc.services.visualstudio.com https://az416426.vo.msecnd.net https://code.jquery.com https://maxcdn.bootstrapcdn.com https://www.facebook.com https://cdn.jsdelivr.net https://*.episerver.net https://*.bing.com https://*.virtualearth.net https://*.googletagmanager.com https://*.google-analytics.com https://policy.app.cookieinformation.com/ https://www.googleadservices.com https://snap.licdn.com https://sc-static.net https://connect.facebook.net https://tr.snapchat.com/collector/ https://*.econa.no https://analytics.tiktok.com https://tr.snapchat.com https://cxppusa1formui01cdnsa01-endpoint.azureedge.net https://public-eur.mkt.dynamics.com https://assets-eur.mkt.dynamics.com https://apitest.vipps.no/ https://checkout.vipps.no; style-src '- strict-transport-security
max-age=2592000